Re: Not! the same DNS records for different checks

Raymond S Brand <[email protected]> Sun, 26 Oct 2003 14:46:42 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Hadmut Danisch wrote:
> 
> On Sun, Oct 26, 2003 at 12:41:05AM -0400, Yakov Shafranovich wrote:
> > My question to you guys is as follows:
> >
> > There are two approachs outlined here:
> > 1. HELO checks.
> > 2. MAIL FROM checks.
> >
> > These different types of checks - can they rely on data stored in the
> > same DNS records - can we use the same DNS record for both checks?
> 
> I'm currently writing down what I consider to be a unified proposal,
> and I am elaborating a little bit into security engineering, thus
> focussing on the difference between authentication and authorization,
> and such things.
> 
> While writing I found a significant and important difference between
> HELO and MAIL FROM:
> 
> The MAIL FROM verification is solely an authorization check. The
> identity is basically the IP address itself (which we get cheap and do
> not need to care about), and we ask "Is the entity with this identity
> (=ip address) authorized to do this and that?"
> 
> In contrast, the HELO check is a completely different story:
> 
> - Two identities: IP address and Hostname
> - Our question: "Are you really Hostname?"
> - So it is only a matter of authentication
> - No authorization
> 
> Since we want to ask the domain authority whether this particular
> machine has really this particular hostname, it is just a 1:1
> relation and authentication. We do not need the RMX/SPF/... overhead
> to do so, because our proposals are mainly authorization mechanisms.
> To be precise, they are useless here because we don't need
> authorization at HELO.
> 
> So the question is: Wouldn't a simple A query to the given hostname
> and the verification whether the response meets the peer's IP address
> to the appropriate tool and just cover the authentication question?
> 
> If we already agree that the EHLO parameter is a hostname, and the
> domain owner has to just confirm that this hostname belongs to this
> machine, so what could our proposals do any better than a simple
> A record?

How does this tell you that the hostname is authorized to relay mail?


Raymond S Brand