5 ms·
The dirty secret nobody wants to talk about is that MTA's don't do certificate validation. You can't or you'd never deliver email successfully because of the nu
by feld 10y ago
The dirty secret nobody wants to talk about is that MTA's don't do certificate validation. You can't or you'd never deliver email successfully because of the number of self signed certs out there.
MITM on SSL/TLS SMTP is child's play
- yellowapple 10y agoHopefully Let's Encrypt (and ACME in general) and similar efforts will help to alleviate that issue. Let's Encrypt in particular seems to be more geared toward websites, but I actually did manage to put it to use rather trivially on my mailserver (which previously used self-signed certs) thanks to 'acme-client' on OpenBSD.
- mike-cardwell 10y agoPostfix and Exim both support DANE/TLSA. When I email somebody with TLSA set up, or they email me, the certificates are validated using DNSSEC signed DNS records: mike@snake:~$ dig +short mx grepular.com 20 mail.grepular.com. 10 mx1.grepular.com. mike@snake:~$ dig +short tlsa _25._tcp.mx1.grepular.com 2 1 1 60B87575447DCBA2A36B7D11AC09FB24A9DB406FEE12D2CC90180517 616E8A18 2 1 1 B111DD8A1C2091A89BD4FD60C57F0716CCE50FEEFF8137CDBEE0326E 02CF362B mike@snake:~$ dig +short tlsa _25._tcp.mail.grepular.com 2 1 1 B111DD8A1C2091A89BD4FD60C57F0716CCE50FEEFF8137CDBEE0326E 02CF362B 2 1 1 60B87575447DCBA2A36B7D11AC09FB24A9DB406FEE12D2CC90180517 616E8A18 mike@snake:~$
- cuckcuckspruce 10y agoThat assumes that nobody can MITM either your DNS server, the your ISPs DNS cache (if you use it), or Google's DNS cache (if you use it).
- noinsight 10y agoOr it assumes DNSSEC.
- mike-cardwell 10y agoIt does assume DNSSEC yes. Which is a requirement of DANE.
- feld 10y agoWho are you emailing? Gmail/yahoo/other technically competent organizations? Try working with small businesses, lawyers, etc who self-host. It will fail and clients will scream bloody murder unless you turn off validation so their emails can get delivered.