Re: Not! the same DNS records for different checks

Richard Rognlie <[email protected]> Sun, 26 Oct 2003 15:10:57 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
On Sun, Oct 26, 2003 at 08:59:21PM +0100, Hadmut Danisch wrote:
> On Sun, Oct 26, 2003 at 02:46:42PM -0500, Raymond S Brand wrote:
> > 
> > How does this tell you that the hostname is authorized to relay mail?
> 
> 
> Well, until now I did not see that this is a desirable goal to be
> achieved.
> 
> 
> I was under the assumption that there is only one authorization step, 
> the authorization be the sender address domain. If this is impossible
> (odd forwarding, empty sender address), then I thought that it is
> desired to see which domain the sending machine belongs to in order to 
> allow later blaming.
> 
> I was not aware that we want to provide an additional authorization by
> the owner of the domain where the HELO name belongs to, which means
> that there are two distinct kinds of machines in this domain,
> authorized ones and those, which belong to the domain but are not
> authorized. 
> 
> I understand that DRIP copes with this problem, but I was and am 
> not aware that we actually do have this problem and do want to solve
> this problem. I actually don't know of any network at the moment which
> would want to have such records (because they use firewalls or simply
> do not want to restrict it).
> 
> Don't get me wrong, I do not object. I'm still uncertain that this 
> solves a problem that we have to solve and is of real use. Convince
> me.

Firewalls would, indeed, restrict it.  But that also assumes that
*EVERYONE* has and uses firewalls.  In fact, many sites use firewalls
to restrict inbound traffic, but not outbound.

So, assume you are one of these "promiscious" sites.  and one of my
machines gets infected with some virus or another.

And it goes through my address books and starts doing direct to MX
spamming as its controller mandates.

DRIP allows us to say.. "no.  you should not expect any mail directly
from desktop machine x.y.z.t (HELO desktop.domain.com)"   And as the
domain adminstrator, I can mandate that any machine in my domain use
MTA foo.domain.com as the outbound relay... and *that* machine can have
appropriate access controls to say... "yes.  allow machine x.y.z.t to 
relay out... and I'll do whatever virus detection/flow control/etc.
there"

Something like this in place pre-sobig(et al.) would have nipped those
in the bud.   (of course, it assumes sufficient penetration to make it
worth while, which means consolodating our efforts to make the DNS
admin's side of the equation not too onerous)

Richard

-- 
 /  \__  | Richard Rognlie / Sultan of Sendmail / Gamerz.NET Lackey
 \__/  \ | http://www.gamerz.net/rrognlie/ <rrognlie at gamerz.net>
 /  \__/ | 
 \__/    | CAUTION: may contain Mature material......but I doubt it.