Re: draft-klensin-rfc2821bis-04: VRFY and EXPN syntax

2007-07-16 20:20:23

At 15:08 -0400 on 07/15/2007, John C Klensin wrote about Re: draft-klensin-rfc2821bis-04: VRFY and EXPN syntax:

Partially because of the circumlocutions and security consideration issues, there is a lot of text about VRFY and EXPN in 2821bis.

If I may put in my 2 cents, I'd like to hopefully see some comments about the security issues in using VRFY and EXPN in the security section (if they are not already there) as well as an EXPLICATE MUST that the EHLO reply ONLY list them if they have not been turned off (IOW: If you are going to reject them or send a "Send Me A massage" reply to an attempt to VRFY then do not advertise support for them in the first place).