Re: 9 reasons for dynamic authorization records
Hadmut Danisch <[email protected]> Fri, 13 Feb 2004 20:01:36 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Feb 13, 2004 at 04:37:44PM +0100, Patrik Fältström wrote: > > (a) What is the problem with updating the zonefile every second? I > don't see any problems at all with it. If you said 100 times a second, > sure, then we can talk about potential issues, but once? Is that something we would really like to support? It would at least break normal DNS servers used as secondaries. Of course, you could write special DNS servers, which do that. But that's a contradiction in terms. Read your own argument: You're objecting my proposal about dynamicly generating authorization records with a proposal to update the zone table every second (and consequently leave the SOA expiry and TTL short). What is that if not a dynamic authorization record? Should this be an argument against dynamic authorization records? But If you agree that authorization records are to be updated dynamically or within short time intervals, why do you want to modify or reinvent DNS and replace DNS servers if there is the better solution with HTTP servers and CGI scripts which doesn't need any protocol or implementation to be raped and which is already there, widely implemented, ready to be used and mastered by many sysops? > (b) You seem to think, or I have missed something, that the end user is > sending things directly from wherever they are on the network? At least I know many users who do so and I received many complaints about RMX from users who felt handicapped because the first version of RMX did not explicetely support this. That's why I included a section about DynDNS records. However, they are still not sufficient, and several complainers expressed to be not willing to reveal their mail infrastructure (including some three letter organizations). This is not only about the end user. > As Alan said, there are two correct solutions for this: A VPN > connection to the "home network" or use of SMTP AUTH with an > outgoing relay-MTA which is at a fixed point in the world (in the > "home network"). That's what I proposed in the RMX drafts (e.g. I prefer to exchange mail with my "home network" through uucp over ssl, which works perfectly well), but there are so many people who do not want to do this. Some of them claimed to be violated in their freedom of speech. But others have better reasons. And some have three letters. > You seems to definitely have a very very special network design which > you use for this and other arguments of yours, and it seems people > don't agree with that design. Huh? As I said, my network design doesn't play a role here, since I do not even use SMTP to exchange E-Mail with my "home relay", which has a static address. So my "special network" definitely does not affect my proposal in any way. But I believie it's somehow malicious to insinuate that I would do this just because of my personal "special network". That's pure nonsense. Many other people in IETF working groups have experience with their own private network only, but not me. I'm working as a professional security consultant for many years now and have seen and advised dozens of companies and their networks, and have seen the problems they have with their remote users, spread all over Europe and some world wide, including the USA. I have advised companies with highest security requirements and written an expertise for the german government which was partly reprinted where the government publishes it's laws. And I published RMX in December 2002, a long time before the other drafts flying around here had been written. I followed thousands of mails from the first months of the ASRG mailing list, and received several hundreds of comments outside the list. Thus I have discussed using RMX with a lot of people, and have heared their opinion. That's what I base my experience on. So your statement is pure nonsense. This is not about "my very very special network design which I use for this and other arguments". You would do much better to use objective arguments instead of attacking people personally and trying to ridicule their proposals. Try to be less biased. regards Hadmut