ietf-mxcomp
[Top] [All Lists]

Re: Authentication and Authorization

2004-03-12 07:28:58


ned,


That is, the policy comes from the domain owner; the server SMTP decides
whether to conform to it.

nfmc> Right, although there might be some issues surrounding what "domain 
owner"
nfmc> means.

indeed, I thought a bit about that, before sending the previous note,
but decided it was a factorable question.  (in other words, our efforts
at precision will require dealing with the point, but it did not seem
essential to include it in the previous round of posting.)

but now that you've brought it up, I suggest that we be strictly
operational:  the domain owner is whoever has control over the RRs in the
DNS, that are associated with the domain name.

Seems reasonable enough to me.

nfmc> Not only do we have proposals that use different parts of the DNS in
nfmc> different ways, there's the mundane but nevertheless real issue that
nfmc> administrative control over a domain's email policies and administrative
nfmc> control over a domain's DNS entries may not be the same.

oh boy.  yes.  but i think that we cannot do much about that, other than
to suggest that mail senders have a domain name that RR records is under the
control of the email administrators...

I agree it isn't something we can fix, but it is another issue to keep
in mind. The list is long...

However, as always, an agreement at a face-to-face meeting needs to be
confirmed online.

nfmc> Agreed, and it is all the more important here since the meeting ran 
late and
nfmc> the question didn't get posed until some people had left.

and attendance by the usual suspects was quite poor, at this ietf, and...

Yep. More than the usual caveats apply.

                                Ned