Re: sender vs author, channel vs object, designated sender vs crypto signatures
2004-03-18 10:38:54
Meng,
MWW> | Using Mail From to authenticate a role involved with authorship or
MWW> | posting (initial sending) will break those legitimate uses and will
MWW> | remove an important capability from Internet mail.
MWW> I'm not sure what point you're making. Are you saying that the RFC2821
MWW> MAIL FROM should not be the subject of autentication at all?
I'll assume that your later posts cover this concern.
MWW> 1) I believe that it is important to protect the RFC2821 MAIL FROM from
MWW> illegitimate spoofing, independent of the RFC2822 header From:.
That phrasing sounds like an assertion that we can have productive
discussion about.
Even worse (...) it sounds like a pretty reasonable goal, since I am
sure folks will agree that unauthorized use of bounces addresses is a
serious problem.
MWW> 2) I believe that the most appropriate way to do so is with a designated
MWW> sender scheme.
When the working group starts debating particular schemes for achieving
the desired authentication (and maybe authorization) we can pursue of
this scheme, and others, further.
MWW> 3) I believe that it is also important to protect the RFC2822 header From:
MWW> from illegitimate spoofing, independent of the RFC2821 MAIL FROM.
Hard to argue with that view. (Although, of course, a community like
this can argue about anything...)
d/
--
Dave Crocker <dcrocker-at-brandenburg-dot-com>
Brandenburg InternetWorking <www.brandenburg.com>
Sunnyvale, CA USA <tel:+1.408.246.8253>
<Prev in Thread] |
Current Thread |
[Next in Thread>
|
- sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Dave Crocker
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, wayne
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Dave Crocker
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures,
Dave Crocker <=
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Yakov Shafranovich
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Mark C. Langston
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Yakov Shafranovich
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Mark C. Langston
- Re: sender vs author, channel vs object, designated sender vs crypto signatures, Dave Crocker
Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong
|
Previous by Date: |
Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong |
Next by Date: |
Re: Draft Charter milestone sequence, Dave Crocker |
Previous by Thread: |
Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong |
Next by Thread: |
Re: sender vs author, channel vs object, designated sender vs crypto signatures, Meng Weng Wong |
Indexes: |
[Date]
[Thread]
[Top]
[All Lists] |
|
|