[ietf-dkim] Re: ISSUE 1521 -- Limit the application of SSP to unsigned messages

Arvel Hathcock arvel.hathcock at altn.com
Thu Jan 24 11:31:04 PST 2008


 > -1 also. I'd go farther and say that it would make the entire protocol
 > completely useless.

-1

Mike is entirely right.  SSP is dead-on-arrival and we've all completely 
wasted our time if this proposal is allowed to stand and here's why:

SSP is about providing the receiver with a means to check whether a 
required message characteristic is missing.  SSP settles on 4871 for the 
"characteristic" and a From: header domain check for the "required".  If 
we remove the "required" we're left only with the bare "characteristic" 
which tells us nothing useful except in cases where there's a 
preexisting trust.

Arvel




More information about the ietf-dkim mailing list