Re: A permission to re-sign header

"John R Levine" <[email protected]> 18 Apr 2014 11:44:00 -0400
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
>> This is a permission to re-sign for a message From:
>> [email protected], to be re-signed by a mailing list at ietf.org. The
>> s= and a= and t= are the same as DKIM, the b= is a signature of a hash
>> of the M-R header, similar to the b= signature in a DKIM-Signature.
>> [...]
>
> Could the same thing be accomplished by a slight adjustment to VBR,
> allowing a zone to vouch for another with the specific meaning that this
> means X is authorized to generate mail for Y as long as X signs it?

VBR is just a hint saying go look at a whitelist.  It has no inherent 
security and only works because it assumes the receiver already knows what 
whitelists it trusts.  (This must be obscure, too many people told us VBR 
was stupid because anyone could build a fake whitelist and point VBR 
headers at it.)

Do you mean that every DMARC publisher would have its own exception 
whitelist, and the adjustment would be to assume the whitelist is credible 
if its name matches the From: domain?  I suppose that could work, although 
expecting every domain to publish its own whitelist seems unlikely to 
scale.  A domain could indirectly use someone else's domain whitelist via 
DNAME, but urrghh.

If we expect there to be a handful of widely used DMARC exception 
whitelists, a mailing list could certainly use VBR as defined to point at 
the whitelist(s) in which its signing domain is included.

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail.

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822
smime.p7s (application/pkcs7-signature, 2.2 KB) - not displayed