Re: Devilish: Forget about DNS
Jeff_Silverman <[email protected]> Mon, 9 Feb 2004 11:26:50 -0800 (PST)
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <Pine.LNX.4.44.0402091121150.24528-100000@angel> |
On Mon, 9 Feb 2004, Hadmut Danisch wrote: > On Mon, Feb 09, 2004 at 01:33:21PM -0500, Yakov Shafranovich wrote: > > > > Perhaps we should just reformulate the problem as: > > > > How do we introduce sender authentication into the email system? > > > > Exactly. But until now, by far too many time was wasted to > dance around the problem how to find workaround for the > flaws and limitations of DNS. > > DNS is made for finding IP addresses for domain names. That's what we > should use it for. > > DNS is not made for transporting other information hidden in it's > record types by violation of their meaning. That's what we should > not use it for. > > Hadmut > So why not use kerberos, which was designed to authenticate things? I have been having a discussion with Yakov on this idea on the side, and Yakov raises the (serious and valid) objections that a bad guy could create his/her own evil authentication server. Alternatively, a centralized authentication server has the potential of being taken over by an organization with corrupt business practices (I won't name names here). More thought is required as to how the authentication server would authenticate an E_mail sender, but this problem might be a "real world" problem that any authentication may have to deal with. The "trusted 3rd party kerberos or kerberos-like authentication server" idea is not fully cooked yet, and I would appreciate a wider discussion of some of the pros and cons. Many thanks, Jeff