On Thu, Oct 19, 2017 at 10:03 AM, Daniel Margolis <dmargo...@google.com>
wrote:

> Yes, I also don't see the point of vanity hosts, but I guess some people
> want this for some reason.
>
> Ivan's language seems fine to me, for the most part, but I still wonder if
> it wouldn't make STS implementation harder for MTA developers than the
> alternative (which is to just say you can't use SNI with STS).
>

Why would it make implementation harder? SNI has been widely supported for
a very long time in client libraries.


I don't see anyone else weighing in here, though, which makes me think
> nobody cares too much about it. Let's see if changing the subject causes
> renewed interest. ;)
>
> On Wed, Oct 18, 2017 at 9:39 PM, Viktor Dukhovni <ietf-d...@dukhovni.org>
> wrote:
>
>>
>>
>> > On Oct 18, 2017, at 3:29 PM, Daniel Margolis <dmargo...@google.com>
>> wrote:
>> >
>> > Viktor, wearing your MTA-developer hat, any objections to requiring the
>> MTA to always send SNI? I don't know what common MTAs do about sending SNI.
>>
>> At present, Postfix always sends SNI when doing DANE and never otherwise.
>> The STS logic could be the same.  Mind you, SNI does introduce a privacy
>> leak, since SNI is sent in the clear.  So one could take the view that
>> the need for this is slim, and that the motivating use-case is not
>> compelling.  Or one could support virtual-hosted "vanity" aliases for
>> MX hosts.   Given DNS indirection from the domain to the MX hosts, the
>> case for virtual-hosting with alternate chains is much weaker in SMTP.
>>
>> So I am reluctant to recommend SNI support for STS, but also not saying
>> that it should not be supported.  I'd like to see the WG consider the
>> pros and cons and choose accordingly.
>>
>> I'm fine with either outcome.
>>
>> --
>>         Viktor.
>>
>> _______________________________________________
>> Uta mailing list
>> Uta@ietf.org
>> https://www.ietf.org/mailman/listinfo/uta
>>
>
>
> _______________________________________________
> Uta mailing list
> Uta@ietf.org
> https://www.ietf.org/mailman/listinfo/uta
>
>


-- 
Ivan
_______________________________________________
Uta mailing list
Uta@ietf.org
https://www.ietf.org/mailman/listinfo/uta

Reply via email to