Re: Mailing lists - assumptions

Pete Resnick <[email protected]> Sun, 20 Apr 2014 10:32:38 -0500
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
On 4/19/14 6:18 PM, John R Levine wrote:
> Now I'm really confused.  Untill a few minutes ago I was saying the 
> token has to be signed, and you were (as far as I can tell) saying it 
> doesn't. Now we seem to agree.

No, you must have misunderstood. I always agreed that the token had to 
be signed. I only disagreed that there had to be some sort of 
"re-signing" of the original message, or that anything that the 
originator sent needs to sent, unmolested, to the list recipients. Once 
the originator has sent the message with its token to the list, the list 
will be able to forward the token (or some modification of the token) 
such that the eventual recipient can cryptographically verify that:

1. The message came arrived directly from the list's server (e.g., using 
DKIM with the list's server).
2. The token in the message indicates that the list got the message 
directly from the originator's server.

pr

-- 
Pete Resnick<http://www.qualcomm.com/~presnick/>
Qualcomm Technologies, Inc. - +1 (858)651-4478

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822