Re: Working group last call on draft-ietf-sieve-include

Robert Burrell Donkin <[email protected]>
Newsgroups gmane.ietf.mta-filters
Message-ID <CAKTa1mhyYABfH=vuS-6d_9hAJozBErUu077LODb5kPB268dwDA@mail.gmail.com>
On Sat, Sep 24, 2011 at 4:08 PM, Alexey Melnikov
<[email protected]> wrote:
> Aaron Stone wrote:

<snip>

>> In the case of a MUST, it means that a valid includes implementation
>> imposes a script naming restriction. If a site isn't using
>> managesieve, would that site really need to accept the name
>> restrictions?
>>
> If you don't make it a MUST, then nobody can be relied upon the rule.

I'm a little unclear why allowing people to rely on this rule should
be seen as good thing...

1. Can anyone think of a use case that could be satisfied best by an
author intentionally including a restricted script name?

2. Allowing implementors to rely on this rule may create a false sense
of security, and so may encourage them to neglect proper checks on
names before accessing their backing store. What are the positive
benefits that outweigh this risk?


In any case, I think reminding people about potential attacks in "4.
Security Considerations" would be useful, so I would like to see
something like [1] included

Robert

[1] Sieve implementations MUST check that script names are safe for
use with their storage system. Any script including a name which could
be used as a vector to attack the system used to store scripts MUST be
rejected.
_______________________________________________
sieve mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sieve
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.