Re: submission vs smtp

Michael Richardson <[email protected]> Thu, 05 Jun 2025 16:27:46 -0400
Newsgroups gmane.mail.nmh.devel
Message-ID <[email protected]>
Ken Hornstein <[email protected]> wrote:
    > Fair enough; I'm not saying that the protocol doesn't exist, it just
    > seems like it's extremely uncommon.  BTW, does that require the TLS
    > client EKU in the client certificate?  It seems like that's going away
    > from certificates issued by most public CAs, at least ones that want to
    > be part of the Chrome root certificate program.

I don't care, I pin the certificate on the SMTP relay via fingerprint.

    > Also, I do have to ask why you don't use something like SASL, which has
    > much wider client support (and I know postfix supports that).

Because none of that worked in 1998 :-)

SASL would require some kind of sign in; which means that the cron jobs on my
laptop (and other cloud machines which send reports via authenticated SMTP),
would have to have some account.
signature.asc (application/pgp-signature, 511 B)
-----BEGIN PGP SIGNATURE-----

iQFFBAEBCgAvFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhB/cIRHG1jckBzYW5k
ZWxtYW4uY2EACgkQgItw+93Q3WVZTAf+Ph97pbH7oqvu23Lr3snSUsOeS8ammM5J
CrZeJiBLHzwLKgLMrMqRoBCl0FYKyKAD8Vnbz2oo1wZRuniiOYQp6oHaWDOtutPv
Fzk1FhAv5tBAJC8AEUxxtEvVT7qMCZ5dcbNpE3z3D0boyPJO9lI+uGPbs6bYZ/JJ
xaQU4xrpcU06QogIVrNfV1oEDqbt28DVFuBwrZ5bqSz4ODlEm+PbiWcQOZmBTksm
SzbjGYPG2B1eosszwmgQgYhT9dr0lZp2podV4IxAHOltSGayJuWpZgrzsw0A1EWv
4G1xTVmcTiOZiK7p5Su6VppgolS76EGNvgXUJq93xOVXE39UgbGBXA==
=74S5
-----END PGP SIGNATURE-----