[saag] Initiating discussion on normative evolution of email p rotocols to enforce mandatory encryption and digital signature

adums <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
 Greetings,

 1.  Background
Email remains the primary electronic communication channel used across
public institutions, private enterprises, and personal exchanges. Despite
its ubiquity, the underlying protocols (SMTP, MIME, etc.) do not enforce
encryption or authentication of message content by default.
Existing standards such as S/MIME (RFC 8551) and OpenPGP (RFC 4880) provide
mechanisms for encryption and signing, but their adoption remains limited
due to usability challenges, lack of interoperability, and absence of
transparent integration in mainstream email clients.

2.  Problem Statement
Highly sensitive data - including medical records, legal documents, and
personal identifiers - is routinely transmitted via email in plaintext,
exposing users to interception, manipulation, and privacy breaches. This
situation is incompatible with modern expectations of confidentiality and
data protection, especially under frameworks like GDPR.

3.  Objective
This proposal aims to initiate a formal discussion within the IETF community
to explore the creation of an Internet-Draft that would:
- Mandate encryption of email content, beyond opportunistic TLS, ensuring
confidentiality at rest and in transit.
- Require digital signatures for all email messages, to guarantee integrity
and authenticity - even in cases where encryption is not applied.
- Define a standardized mechanism for public key discovery, such as
DNSSEC/DANE or a federated PKI.
- Introduce a new MIME header indicating encryption/signature requirements
and compliance.
- Establish a transition roadmap toward deprecating unencrypted and unsigned
email delivery.

4.  Technical Considerations
While implementation details are open to discussion, potential directions
include:
- SMTP extensions that reject or encapsulate unencrypted or unsigned
messages.
- Mandatory support for S/MIME or OpenPGP in all major email clients, with
simplified key management.
- Compatibility with existing anti-spam and authentication mechanisms (SPF,
DKIM, DMARC).
- Integration with secure transport protocols and metadata protection.

5.  Call to Action
This is a citizen-driven initiative, not a finalized technical draft. Its
purpose is to encourage IETF members to consider drafting a formal
Internet-Draft addressing mandatory encryption and signature. Invite
feedback from protocol designers, security experts, and client developers.
Raise awareness among users and professionals about the risks of plaintext
and unsigned email.
To the best of my knowledge, no RFC has yet proposed a mandatory
encryption-and-signature framework for email protocols as a normative
requirement. If such a proposal exists, I would be grateful for any
references.


6.  Closing Thoughts
Email is a cornerstone of digital communication. It is time to align its
technical standards with the ethical and legal imperatives of
confidentiality, integrity, and trust. This proposal is a starting point -
and I hope it finds resonance among those with the expertise and influence
to carry it forward

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.