RE: Man In The Middle Attacks and STARTTLS
Paul Hoffman / IMC <[email protected]> Thu, 15 Apr 1999 16:20:11 -0700
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
At 03:54 PM 4/15/99 -0700, Scott Roberts (Exchange) wrote: >Bodo, your points are good. I would think that it is better to state that a >reasonable amount of time SHOULD pass before the message is returned to the >sender rather than stating a default time because of issues that might arise >in the future. You are only seeing two options: use TLS or return to sender. The third option, which I think will get used much of the time, is send anyway. That is, various client-server pairs with lots of cycles to spare might be willing to use STARTTLS to encrypt because it only causes a second or two delay and, hey, why not. If TLS isn't available, they'd send the mail anyway. >We could add to section 5 stating: > A client that receives a 454 reply code from a server that has >advertised the STARTTLS verb SHOULD attempt to retry the mail in a >reasonable amount of time or reroute it before returning it to the sender. >The amount of time before retrying the message and/or NDRing the message >should be left up to the implementation and is outside the scope of this >document. I think the wording needs to cover much more than that. I'll work on some and stick it in the first draft, and we can discuss from there. --Paul Hoffman, Director --Internet Mail Consortium