nanog mailing list archives
Re: Massive change in Public Cert behaviour coming soon
From: "John R. Levine via NANOG" <nanog () lists nanog org>
Date: 22 May 2025 17:21:21 -0400
On Thu, 22 May 2025, Jay Acuna wrote:
This does not work for applications where the client authentication is between servers at different organizations. Such as the SMTP server or Web server which wishes to connect to another company's SMTP server or Web server using mutual TLS to verify the web server FQDN for authentication to send mail or access an API endpoint as that server's identiy.
This is sounding awfully hypothetical. I have seen a lot of SMTP software and I have never, ever, seen one send a client certificate in an SMTP session. Submission clients sometimes use them, but that's different, and the client cert is provided by whoever runs the server.
Mail servers either check the client's IP address with SPF, which works poorly for a variety of reasons, or there's a DKIM signature in the message the client sends, unrelated to the SMTP transport.
R's, JohnPS: in the IETF we are nearly done with a long overdue update to RFC 5321 and I can assure you there is not a whiff of client certs there either.
_______________________________________________NANOG mailing list https://lists.nanog.org/archives/list/nanog () lists nanog org/message/FS3UXBW4DARFXL4GC47VNVSEMRYGJG3I/
Current thread:
- Re: Massive change in Public Cert behaviour coming soon, (continued)
- Re: Massive change in Public Cert behaviour coming soon Tom Beecher via NANOG (May 19)
- Re: Massive change in Public Cert behaviour coming soon William Herrin via NANOG (May 19)
- Re: Massive change in Public Cert behaviour coming soon Crist Clark via NANOG (May 18)
- Re: Massive change in Public Cert behaviour coming soon William Herrin via NANOG (May 18)
- Re: Massive change in Public Cert behaviour coming soon brent saner via NANOG (May 18)
- Message not available
- Message not available
- Message not available
- Message not available
- Message not available
- Re: Massive change in Public Cert behaviour coming soon Crist Clark via NANOG (May 27)
- Message not available
- Message not available
- Message not available
- Message not available
- Message not available
- Re: Massive change in Public Cert behaviour coming soon Tom Beecher via NANOG (May 27)
- Message not available
- Message not available
- Message not available
- Message not available
- Message not available
- Re: Massive change in Public Cert behaviour coming soon Colin Constable via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon John Levine via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon Jay Acuna via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon John R. Levine via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon Eliot Lear via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon Jay Acuna via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon John R. Levine via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon Bjørn Mork via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon John Levine via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon William Herrin via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon John Levine via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon Bjørn Mork via NANOG (May 27)
- Re: Trivial change in Public Cert behaviour coming soon Michael Thomas via NANOG (May 27)
- Re: Massive change in Public Cert behaviour coming soon John R. Levine via NANOG (May 27)
