From Newsgroup: comp.mail.sendmail
In the IETF we're having a rather tedious fight about an upcoming revision to the mail standards, between people who understand mail and don't want to break backward compatibility, and people who don't and insist that the new standard require all mail to use STARTTLS.
In today's skirmish, one of the TLS crowd says:
1. [Current text] Requiring all email server developers to write code to accept unencrypted mail, even if none of their users wants it
2. [Deleting the MUST] Allowing email server developers to skip the non-secure code if they only want to serve users who accept the tradeoffs
So my question is, imagine a hypothetical version of sendmail that was STARTLS only.
How much code are we talking about here?
As far as I can tell, the difference would be to add about six lines of code to check that TLS had started before a MAIL, RCPT, or DATA command., and there's nothing to delete. Am I missing anything?
--
Regards,
John Levine,
johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail.
https://jl.ly
--- Synchronet 3.22a-Linux NewsLink 1.2