Re: Not! the same DNS records for different checks
Raymond S Brand <[email protected]> Sun, 26 Oct 2003 14:46:42 -0500
| Newsgroups | gmane.ietf.asrg.rmx |
|---|---|
| Message-ID | <[email protected]> |
Hadmut Danisch wrote: > > On Sun, Oct 26, 2003 at 12:41:05AM -0400, Yakov Shafranovich wrote: > > My question to you guys is as follows: > > > > There are two approachs outlined here: > > 1. HELO checks. > > 2. MAIL FROM checks. > > > > These different types of checks - can they rely on data stored in the > > same DNS records - can we use the same DNS record for both checks? > > I'm currently writing down what I consider to be a unified proposal, > and I am elaborating a little bit into security engineering, thus > focussing on the difference between authentication and authorization, > and such things. > > While writing I found a significant and important difference between > HELO and MAIL FROM: > > The MAIL FROM verification is solely an authorization check. The > identity is basically the IP address itself (which we get cheap and do > not need to care about), and we ask "Is the entity with this identity > (=ip address) authorized to do this and that?" > > In contrast, the HELO check is a completely different story: > > - Two identities: IP address and Hostname > - Our question: "Are you really Hostname?" > - So it is only a matter of authentication > - No authorization > > Since we want to ask the domain authority whether this particular > machine has really this particular hostname, it is just a 1:1 > relation and authentication. We do not need the RMX/SPF/... overhead > to do so, because our proposals are mainly authorization mechanisms. > To be precise, they are useless here because we don't need > authorization at HELO. > > So the question is: Wouldn't a simple A query to the given hostname > and the verification whether the response meets the peer's IP address > to the appropriate tool and just cover the authentication question? > > If we already agree that the EHLO parameter is a hostname, and the > domain owner has to just confirm that this hostname belongs to this > machine, so what could our proposals do any better than a simple > A record? How does this tell you that the hostname is authorized to relay mail? Raymond S Brand