Re: Implementation certification procedure

"Stuart D. Gathman" <[email protected]> Wed, 20 Aug 2008 09:26:25 -0400 (EDT)
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
On Wed, 20 Aug 2008, Alessandro Vesely wrote:

> IMHO, the best thing would be to have those tuples published on a web page. If
> it were also possible to post the results in order to have a response, much
> like html validation pages, that would be great!

That is what the test suite is: a collection of such tuples (actually
maps so that the order is explicit).

> In the latter case, if the submitter authenticates and specifies name and
> version of the implementation, it will be trivial to build a database of
> verified implementations, along with the date and test suite version.

Just as important is who did the verification.  Ideally, an independent
3rd party such inspect and run the tests.  But that requires volunteers
or a budget.  In the interim, just documenting who ran the tests - even
if it is someone from the same project - would be better than nothing.

> Validating Received-SPF can be slightly more difficult, since order and
> indentation may vary.

The official test suite doesn't validate received-spf for this reason. 
However, the schema supports adding such tests (and pyspf uses them).
It is trivial for a given implementation since you can check for an
exact received-spf output.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.