Re: Should the IETF be condoning, even promoting, BOM pollution?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



(In case that was too flippant, my point is that RFC 4217 is really what we now call opportunistic security, and any kind of actual authentication of the endpoint is addressed in the document with a handwave.)

But that basically declares everything that uses a STARTTLS-like machanism 'insecure'. Does that mean they're flagging IMAP, POP, and SMTP/Submission as insecure, too?

If DNSSEC says the A record for foo.example.net is valid, and the FTP TLS negotiation gives me a cert with a CN=foo.example.net, I'd say that's more than hand waving.

--lyndon




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]