[ietf-dkim] Delegating responsibility: a make vs. buy design decision

Michael Thomas mike at mtcc.com
Fri Aug 18 10:49:15 PDT 2006


Scott Kitterman wrote:

>On Thursday 17 August 2006 16:50, Dave Crocker wrote:
>
>  
>
>>This mechanism already exists, is notably simpler than the one being
>>discussed, and does not suffer the security hole that has been noted.
>>
>>Simply stated:
>>
>>     If the author's domain is to be used for assessment activities, then
>>have the signature be made with a domain that is directly related to the
>>author.
>>    
>>
>
>As was already discussed in the comments to the requirements draft, not all 
>DNS providers give their customers the ability to do subdomain level NS 
>delegation and so while that approach is good for those who can do it, it 
>leaves out a portion of the potential user base.
>  
>
Let's be very clear here: not every DNS provider has the ability to do TXT
records either. Those small businesses, etc, should either pressure 
their providers
or vote with their feet.

       Mike


More information about the ietf-dkim mailing list