Re: Problems with spf testsuite and dns specification

Stefano Bagnara <[email protected]>
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
Stuart D. Gathman ha scritto:
> On Tue, 12 Jun 2007, Stefano Bagnara wrote:
> 
>>> Nevertheless, the SPF spec says that when there are multiple TXT
>>> records beginning with "v=spf1", then the correct result is PermError.  
>> That's what I'm trying to fix.  IMHO it is correct when the records are
>> different, but when they are identical it is a matter of what DNS server
>> (servers) and what dns clients are in the resolution chain to know if
>> you will receive one or multiple identical records. The SPF spec should
>> not rely on this: the DNS spec does not allow such distinction to be
>> made and SPF is a DNS based protocol.
> 
> If some client library *did*, however, return multiple identical records,
> then the correct result is PermError.  Your problem is that when testing
> through a live DNS server, it is difficult to reproduce this situation.
> 
> Here are some possible resolutions:
> 
> 1) tag selected tests as "optional for live DNS testing".
> 
> 2) Add multiple results for tests with multiple identical records.
>    There is certainly no ambiguity in using one of 2 duplicate SPF
>    records, so implementations can be considered justified in bending the
>    current spec a little for this case.
> 
> 3) Add an errata for the spec addressing the case of duplicate records.

IMHO is not so smart to have the SPF spec requiring a behaviour from
library implementors while we already know that the behaviour will
change from pass to permerror depending on the dnsserver the user is using.

This is because indipendently from what the SPF record publisher
publishes on his own server the final result will depend also on the
caching server you are querying.

IMHO it would be FAR BETTER to add a clarification to the spec
explaining this particular scenario and allowing the implementors to
treat multiple identical dns record as one single record and this way
allow them to not return PermError *IF* the multiple records are identical.

So #2 and #3 are acceptable to me. #1 is not a correct solution IMO.

Stefano

-------------------------------------------
-----------------------------------------------------------------------
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?member_id=6959932&user_secret=62b4c45f
Powered by Listbox: http://www.listbox.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.