ietf
[Top] [All Lists]

Re: Last Call: draft-ietf-opes-smtp-security (Integrity, privacy and security in OPES for SMTP) to Informational RFC

2007-01-06 13:48:23
The IESG wrote:

<draft-ietf-opes-smtp-security-02.txt> as an Informational RFC

The "bypass" construct apparently includes what's also known as 
"challenge response scheme".  If that's the case it's net abuse,
unless the challenge is guaranteed to be sent to the originator.

The only relevant case where that's guaranteed I'm aware of is an
SPF PASS.  Even in that case some originators might consider the
challenge as abusive, but at least it's not unsolicited, and they
can stop their communication attempts with such OPES receivers.

But the general case is no SPF PASS, and then the challenge goes
most probably (near 90%) to innocent bystanders.

Frank



_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/ietf