
jbglube at sympatico
Oct 26, 2004, 2:47 AM
Post #2 of 8
(4841 views)
Permalink
|
|
RE: Practical guidance for ESP's (SPF renamed to SenderID?)
[In reply to]
|
|
From: Jeremy Pullicino Sent: October 26, 2004 3:57 AM <snip> |I understand that technically SPF and SenderID are |practically the same thing and that now Microsoft has |removed patents, making SenderID acceptable to companies |such as AOL who have already announced renewed support for |it. <snip> As to your technical conclusion, quoting from draft-lyon-senderid-core, the authors, Messrs. Lyon and Wong write: |This document defines a pair of closely-related tests. One |validates a message's Purported Responsible Address (PRA) |as defined in [PRA]. The other validates a message's |Reverse-Path (also known as MAIL-FROM address) as defined |in [SPF]. | |An e-mail sender SHOULD publish information for both tests, |and SHOULD arrange that any mail that is sent will pass |both tests. [.Section 1, Introduction - page 2 of Sender ID: Authenticating Email] The authors go on to write: |The PRA version of the test seeks to authenticate the |mailbox associated with the most recent introduction of a |message into the mail delivery system. In simple cases, |this is who the mail is from. However, in the case of a |third-party mailer, a forwarder or a mailing list server, |the address being authenticated is that of the third party, |the forwarder or the mailing list. | |On the other hand, the MAIL-FROM version of the test seeks |to authenticate the mailbox that would receive Delivery |Status Notifications (DSNs, or bounces) for the message. In |simple cases, this too is who the mail is from. However, |third-party mailers, forwarders and mailing list servers |MUST specify an address under their control, and SHOULD |arrange that DSNs received at this address are forwarded to |the original bounce address. [.Section 2, Problem Statement - page 3 of Sender ID: Authenticating Email] http://www.spfhelp.com/downloads/draft-lyon-senderid-core-00.txt I agree conceptually the approaches for PRA and MAIL FROM authentication are similar. However, the test for the check host function involves authenticating different identities. This can give rise to different results depending on how a sender has arranged his, her or its affairs. On this point, see the following on backward compatibility in the proposal: |Administrators who have already published "v=spf1" records |SHOULD review these records to determine whether they are |also valid for use with PRA checks. If the information in a |"v=spf1" record is not correct for a PRA check, |administrators SHOULD publish either an "spf2.0/pra" record |with correct information, or an "spf2.0/pra ?all" record |indicating that the result of a PRA chek is explicitly |inconclusive. [.Section 3.4, Backward Compatibility - page 6 of Sender ID: Authenticating Email] http://www.spfhelp.com/downloads/draft-lyon-senderid-core-00.txt On the patent issue, I quote from an article published in CNET news: |Among other changes, Microsoft removed language in its |pending patents for Sender ID that could have included |claims to Sender Permitted From, or SPF, a widely used |system for email authentication that was merged with |Microsoft's CallerID for Email to create Sender ID, |according to Microsoft's Ryan Hamlin. http://news.zdnet.co.uk/internet/security/0,39020375,39171356,00. htm However, MS has not withdrawn its patent claim on the concept of PRA operating in combination with CORE, which forms the basis for the technology being licensed under Microsoft's Royalty Free License which is not compatible with the Open Standard Alliance model. John John Glube Toronto, Canada The FTC Calls For Sender Authentication http://www.learnsteps4profit.com/dne.html --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.779 / Virus Database: 526 - Release Date: 19/10/2004 ------- To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?listname=spf-deployment [at] v2
|