Re: A permission to re-sign header
"Murray S. Kucherawy" <[email protected]> Fri, 18 Apr 2014 09:16:03 -0700
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <CAL0qLwbLfzfiqj9dMbxhwDDL1g477KU3HTXn4ns2JPwrjrTW0w@mail.gmail.com> |
On Fri, Apr 18, 2014 at 8:44 AM, John R Levine <[email protected]> wrote: > >> Could the same thing be accomplished by a slight adjustment to VBR, >> allowing a zone to vouch for another with the specific meaning that this >> means X is authorized to generate mail for Y as long as X signs it? >> > > VBR is just a hint saying go look at a whitelist. It has no inherent > security and only works because it assumes the receiver already knows what > whitelists it trusts. (This must be obscure, too many people told us VBR > was stupid because anyone could build a fake whitelist and point VBR > headers at it.) > Do you mean that every DMARC publisher would have its own exception > whitelist, and the adjustment would be to assume the whitelist is credible > if its name matches the From: domain? I suppose that could work, although > expecting every domain to publish its own whitelist seems unlikely to > scale. A domain could indirectly use someone else's domain whitelist via > DNAME, but urrghh. > > If we expect there to be a handful of widely used DMARC exception > whitelists, a mailing list could certainly use VBR as defined to point at > the whitelist(s) in which its signing domain is included. > Right, maybe that's what I had in mind. It seems as though you're essentially suggesting we need a way to confirm a relationship between X and Y, and VBR pretty much does that. Also, it is both the "go look at the whitelist" hint and the specification of how the whitelist is published. -MSK _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822