Re: Working group last call on draft-ietf-sieve-include
Robert Burrell Donkin <[email protected]>
| Newsgroups | gmane.ietf.mta-filters |
|---|---|
| Message-ID | <CAKTa1mhyYABfH=vuS-6d_9hAJozBErUu077LODb5kPB268dwDA@mail.gmail.com> |
On Sat, Sep 24, 2011 at 4:08 PM, Alexey Melnikov <[email protected]> wrote: > Aaron Stone wrote: <snip> >> In the case of a MUST, it means that a valid includes implementation >> imposes a script naming restriction. If a site isn't using >> managesieve, would that site really need to accept the name >> restrictions? >> > If you don't make it a MUST, then nobody can be relied upon the rule. I'm a little unclear why allowing people to rely on this rule should be seen as good thing... 1. Can anyone think of a use case that could be satisfied best by an author intentionally including a restricted script name? 2. Allowing implementors to rely on this rule may create a false sense of security, and so may encourage them to neglect proper checks on names before accessing their backing store. What are the positive benefits that outweigh this risk? In any case, I think reminding people about potential attacks in "4. Security Considerations" would be useful, so I would like to see something like [1] included Robert [1] Sieve implementations MUST check that script names are safe for use with their storage system. Any script including a name which could be used as a vector to attack the system used to store scripts MUST be rejected. _______________________________________________ sieve mailing list [email protected] https://www.ietf.org/mailman/listinfo/sieve