2012-06-22 06:01:06
Arnt Gulbrandsen <arnt(_at_)gulbrandsen(_dot_)priv(_dot_)no> wrote:

RFC 6186

While I greatly applaud that document in every detail, I do wonder... why do
clients ask the user whether to use TLS? whether to use C=D? whether to
perform plaintext or SASL authentication?

I've been wondering that for at least seven years.

I'm currently trying to write draft-fanf-dane-mua which will update RFC
6186 to specify how it is affected by DNSSEC and how to use TLSA records.
It will use TLSA records to indicate that STARTTLS is supported on the
cleartext ports, and encourage MUAs to use that for autoconfiguration.

