Welcome! Log In Create A New Profile

Advanced

Re: Proposed patch to enforce STARTTLS before MAIL FROM

lists--- via nginx-devel
March 05, 2019 02:48PM
On 3/5/19 12:23 PM, Maxim Dounin wrote:
> Not sure it is a good change.

Thank you for your detailed reply and explanation.  I agree with you on
all facets with respect to RFC compliance.  I believe the core issue at
hand is the antiquated language in the current RFC conflicting with
common practice -- several final destination MTAs on the public
Internet, depending on their role/use, do require and enforce TLS
communication only either on a per-sender, per-recipient, or per-server
basis.  That said your rationale for rejecting the patch is accurate and
mirrors similar expressed in Postfix at
www.postfix.org/postconf.5.html#smtpd_tls_security_level regarding 'encypt'.

If you find the proposed patch satisfactory from a technical aspect I
will commit the patch locally for a specific use case which would fall
under the category of 'dedicated servers'.

For your consideration, perhaps a configuration option of:

starttls dedicated;

With the proposed patch would meet both a use case and RFC requirement aspect.Thanks,

Nathan

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

Proposed patch to enforce STARTTLS before MAIL FROM

Community Proposed via nginx-devel 101 March 04, 2019 02:08PM

Re: Proposed patch to enforce STARTTLS before MAIL FROM

Maxim Dounin 31 March 05, 2019 01:24PM

Re: Proposed patch to enforce STARTTLS before MAIL FROM

lists--- via nginx-devel 31 March 05, 2019 02:48PM

Re: Proposed patch to enforce STARTTLS before MAIL FROM

Maxim Dounin 43 March 07, 2019 12:40PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 69
Record Number of Users: 6 on February 13, 2018
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready