Re: 9 reasons for dynamic authorization records

Hadmut Danisch <[email protected]> Fri, 13 Feb 2004 20:01:36 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On Fri, Feb 13, 2004 at 04:37:44PM +0100, Patrik Fältström wrote:
> 
> (a) What is the problem with updating the zonefile every second? I 
> don't see any problems at all with it. If you said 100 times a second, 
> sure, then we can talk about potential issues, but once?


Is that something we would really like to support? It would
at least break normal DNS servers used as secondaries.


Of course, you could write special DNS servers, which do that.

But that's a contradiction in terms. Read your own argument:

You're objecting my proposal about dynamicly generating authorization 
records with a proposal to update the zone table every second
(and consequently leave the SOA expiry and TTL short). 

What is that if not a dynamic authorization record? Should
this be an argument against dynamic authorization records?


But If you agree that authorization records are to be updated
dynamically or within short time intervals, why do you want to 
modify or reinvent DNS and replace DNS servers if there is 
the better solution with HTTP servers and CGI scripts which
doesn't need any protocol or implementation to be raped 
and which is already there, widely implemented, ready to 
be used and mastered by many sysops?





> (b) You seem to think, or I have missed something, that the end user is 
> sending things directly from wherever they are on the network?

At least I know many users who do so and I received many complaints
about RMX from users who felt handicapped because the first version
of RMX did not explicetely support this. That's why I included a
section about DynDNS records. However, they are still not sufficient, 
and several complainers expressed to be not willing to reveal 
their mail infrastructure  (including some three letter organizations).

This is not only about the end user.




> As Alan said, there are two correct solutions for this: A VPN
> connection to the "home network" or use of SMTP AUTH with an
> outgoing relay-MTA which is at a fixed point in the world (in the
> "home network").

That's what I proposed in the RMX drafts (e.g. I prefer to 
exchange mail with my "home network" through uucp over ssl, which
works perfectly well), but there are so many people who do not want to
do this. Some of them claimed to be violated in their freedom of
speech. But others have better reasons. And some have three letters.






> You seems to definitely have a very very special network design which 
> you use for this and other arguments of yours, and it seems people 
> don't agree with that design.

Huh? 

As I said, my network design doesn't play a role here, since I 
do not even use SMTP to exchange E-Mail with my "home relay", which has 
a static address. So my "special network" definitely does not 
affect my proposal in any way.


But I believie it's somehow malicious to insinuate that I would 
do this just because of my personal "special network". That's pure 
nonsense. Many other people in IETF working groups have experience 
with their own private network only, but not me. 

I'm working as a professional security consultant for many years now
and have seen and advised dozens of companies and their networks, and
have seen the problems they have with their remote users, spread all 
over Europe and some world wide, including the USA. I have advised
companies with highest security requirements and written an expertise
for the german government which was partly reprinted where the 
government publishes it's laws.

And I published RMX in December 2002, a long time before the other 
drafts flying around here had been written. I followed thousands of
mails from the first months of the ASRG mailing list, and received 
several hundreds of comments outside the list. Thus I have discussed 
using RMX with a lot of people, and have heared their opinion.

That's what I base my experience on.

So your statement is pure nonsense. This is not about 
"my very very special network design which I use for this and other 
arguments".

You would do much better to use objective arguments instead
of attacking people personally and trying to ridicule their
proposals. 

Try to be less biased.



regards
Hadmut