Re: DANE-TLSA Support?

Sabahattin Gucukoglu via courier-users <[email protected]> Fri, 24 Oct 2025 16:50:08 +0100
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
On 24 Oct 2025, at 01:02, Sam Varshavchik <[email protected]> wrote:
> There is no DANE support in Courier. I have not looked into DANE support, in any notable detail. I can only say that Courier makes DNS queries directly, without using a resolver library, so in theory it should be able to send and process anything in DNS.

Your well-positioned to support it. You just have to tell the user to use a trusted resolver (that is near to them, or accessed via DoT/DoH proxy) and your responsibilities are basically setting the DO (DNSSEC OK) bit in queries, checking the AD (Authenticated Data) bit in responses, and doing lookups on the TLSA records for the corresponding MX records at time of delivery to find out which certificate or key to match and which scope the key or certificate has (end entity, certificate authority). Both GNUTLS and OpenSSL have DANE support routines that know how to perform verification when you feed them the arguments from the DANE record.

Cheers,
Sabahattin



_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users