4 ms·
There is TLS for SMTP, which admittedly doesn't protect the email once it gets to the server, but at least helps en-route. Also, I don't think there's a proble
by cdjk 13y ago
There is TLS for SMTP, which admittedly doesn't protect the email once it gets to the server, but at least helps en-route.
Also, I don't think there's a problem around the fact that most of the time you don't communicate directly with the recipient's smtp server - relaying is definitely a part of SMTP. It would work in the case of running your own SMTP server that you use to relay mail (assuming you encrypt your own SMTP sessions), but you'd need smtp servers to recursively query for the public key if you want to enable relaying.
This is starting to sound suspiciously like DNS, so why not just store the keys there? There are already ways to do that:
http://www.gushi.org/make-dns-cert/HOWTO.html http://www.gushi.org/make-dns-cert/HOWTO.html
Add in DNSSEC records and you can be pretty certain you have the right key.
- pjungwir 13y agoThank you for replying! Relaying does seem like a fatal flaw. DNS seemed like a bad match for per-user information (rather than per-domain), but indeed that HOWTO gives a nice way of working around that. So it's just a question of MUA PGP modules trying that mechanism.