ietf-smtp
[Top] [All Lists]

Re: draft-murchison-lmtp-ignorequota-01

2001-08-30 19:48:46

On Thu, 30 Aug 2001 15:24:19 PDT, Chris Newman said:
RCPT TO:<foo(_at_)example(_dot_)com> 
LDAP=attr:value:attr:value,value:attr:value

And the mail store should trust these values why?

Even though LTMP is a *local* protocol, this is still inviting to be passed
bad data.  If the message store asks the LDAP server itself, it can at
least use whatever security LDAP has to verify that it's talking to the LDAP
server, and at the very least, it knows that it's being given answers to
queries IT asked.

                                Valdis Kletnieks
                                Operating Systems Analyst
                                Virginia Tech