[saag] Initiating discussion on normative evolution of email p rotocols to enforce mandatory encryption and digital signature
adums <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <[email protected]> |
Greetings, 1. Background Email remains the primary electronic communication channel used across public institutions, private enterprises, and personal exchanges. Despite its ubiquity, the underlying protocols (SMTP, MIME, etc.) do not enforce encryption or authentication of message content by default. Existing standards such as S/MIME (RFC 8551) and OpenPGP (RFC 4880) provide mechanisms for encryption and signing, but their adoption remains limited due to usability challenges, lack of interoperability, and absence of transparent integration in mainstream email clients. 2. Problem Statement Highly sensitive data - including medical records, legal documents, and personal identifiers - is routinely transmitted via email in plaintext, exposing users to interception, manipulation, and privacy breaches. This situation is incompatible with modern expectations of confidentiality and data protection, especially under frameworks like GDPR. 3. Objective This proposal aims to initiate a formal discussion within the IETF community to explore the creation of an Internet-Draft that would: - Mandate encryption of email content, beyond opportunistic TLS, ensuring confidentiality at rest and in transit. - Require digital signatures for all email messages, to guarantee integrity and authenticity - even in cases where encryption is not applied. - Define a standardized mechanism for public key discovery, such as DNSSEC/DANE or a federated PKI. - Introduce a new MIME header indicating encryption/signature requirements and compliance. - Establish a transition roadmap toward deprecating unencrypted and unsigned email delivery. 4. Technical Considerations While implementation details are open to discussion, potential directions include: - SMTP extensions that reject or encapsulate unencrypted or unsigned messages. - Mandatory support for S/MIME or OpenPGP in all major email clients, with simplified key management. - Compatibility with existing anti-spam and authentication mechanisms (SPF, DKIM, DMARC). - Integration with secure transport protocols and metadata protection. 5. Call to Action This is a citizen-driven initiative, not a finalized technical draft. Its purpose is to encourage IETF members to consider drafting a formal Internet-Draft addressing mandatory encryption and signature. Invite feedback from protocol designers, security experts, and client developers. Raise awareness among users and professionals about the risks of plaintext and unsigned email. To the best of my knowledge, no RFC has yet proposed a mandatory encryption-and-signature framework for email protocols as a normative requirement. If such a proposal exists, I would be grateful for any references. 6. Closing Thoughts Email is a cornerstone of digital communication. It is time to align its technical standards with the ethical and legal imperatives of confidentiality, integrity, and trust. This proposal is a starting point - and I hope it finds resonance among those with the expertise and influence to carry it forward _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]