Skip to content

Comments upon reading DANE document #4

@abrotman

Description

@abrotman
  1. Search for "is is" and "not not", a couple of typos.
  2. For the section titled "Why use DANE for SMTP?", it seems to be backward. The section first notes the dangers, and it should perhaps instead list the advantages first. Might need to rework that section.
  3. There are two illustrations titled "Mail delivery: TLS with MITM using evil certificate", not sure if that was intentional, seems like the second is about stripping the STARTTLS. Additionally, for that section (and elsewhere), might want to note that some devices intentionally remove STARTTLS from the response. I believe a Cisco PIX was a device that would regularly do this (for "security" reasons).
  4. You may want to include an example where the DNS response was altered in order to send the sender to a different destination, something DNSSEC would help protect against.
  5. I'd have to double check, but I believe that changing only the expiration date of a certificate does not generate a new hash. As such, if you're merely updating expired certs, you may not need to update the TLSA records. (a deployment consideration)
  6. You may want to mention TLSRPT as a way to get some feedback about DANE deployments.

Metadata

Metadata

Assignees

Labels

No labels
No labels
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions