-
Notifications
You must be signed in to change notification settings - Fork 23
Comments upon reading DANE document #4
Copy link
Copy link
Open
Description
abrotman
opened on Jul 30, 2019
Issue body actions
- Search for "is is" and "not not", a couple of typos.
- For the section titled "Why use DANE for SMTP?", it seems to be backward. The section first notes the dangers, and it should perhaps instead list the advantages first. Might need to rework that section.
- There are two illustrations titled "Mail delivery: TLS with MITM using evil certificate", not sure if that was intentional, seems like the second is about stripping the STARTTLS. Additionally, for that section (and elsewhere), might want to note that some devices intentionally remove STARTTLS from the response. I believe a Cisco PIX was a device that would regularly do this (for "security" reasons).
- You may want to include an example where the DNS response was altered in order to send the sender to a different destination, something DNSSEC would help protect against.
- I'd have to double check, but I believe that changing only the expiration date of a certificate does not generate a new hash. As such, if you're merely updating expired certs, you may not need to update the TLSA records. (a deployment consideration)
- You may want to mention TLSRPT as a way to get some feedback about DANE deployments.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Fields
Give feedbackNo fields configured for issues without a type.