Re: draft-klensin-emailaddr-i18n-00

Paul Hoffman / IMC <[email protected]>
Newsgroups gmane.ietf.imaa
Message-ID <p06002002bbc22d823144@[63.202.92.152]>
At 8:58 PM -0500 10/26/03, John Cowan wrote:
>  > In any case, I think it would be good if receivers do not assume that
>>  text is already normalized; they should perform normalization whenever
>>  they want text to be normalized.  Then it will not be necessary for
>>  senders to perform normalization.  The implementation cost is the
>>  same whether the code is inside the senders or inside the receivers.
>
>This is true for person-to-person email, but not for mailing list
>postings, which are formally equivalent.  There, the efficiency is
>much superior if senders MUST normalize and receivers SHOULD check
>normalization, checking being much less costly than normalizing in
>most cases.

It is fairly "costly" both for the sender and for the receiver if the 
receiver (which is an MTA, not an MUA) bounces messages because the 
sender didn't get the same form as the receiving MTA demanded. That 
is, the sender would see an error that he/she could not figure out, 
and the receiver would, well, never receive.

Or are you saying that all receivers should have aliases for all 
possible un-normalized versions into the intended mailbox name?

>  > Forbidding unnormalized text on the wire doesn't do much except to make
>>  troubleshooting more difficult for humans, who cannot see the difference
>>  between normalized and unnormalized text.  It's not as if unnormalized
>>  text is ambiguous.  It makes sense to forbid ambiguous constructions
>>  like "user@foo@bar", but unnormalized text is not ambiguous--you
>>  can determine exactly what was intended by normalizing it yourself.
>
>But if it is signed, you will destroy the digital signature.

The mailbox name is kept in the headers, which are not signed.

>   What is
>worse, a sender of unnormalized text may be able to spoof a receiver.

Could you give an example?

>See the W3C's CharMod draft (http://www.w3.org/TR/charmod) for details.

Maybe I'm dense, but I don't see any spoofing examples there that 
would apply to Internet mail.

--Paul Hoffman, Director
--Internet Mail Consortium
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.