• An hypothetical question

    From John Levine@johnl@taugh.com to comp.mail.sendmail on Sat Sep 26 00:37:15 2026
    From Newsgroup: comp.mail.sendmail

    In the IETF we're having a rather tedious fight about an upcoming revision to the mail standards, between people who understand mail and don't want to break backward compatibility, and people who don't and insist that the new standard require all mail to use STARTTLS.

    In today's skirmish, one of the TLS crowd says:

    1. [Current text] Requiring all email server developers to write code to accept unencrypted mail, even if none of their users wants it
    2. [Deleting the MUST] Allowing email server developers to skip the non-secure code if they only want to serve users who accept the tradeoffs

    So my question is, imagine a hypothetical version of sendmail that was STARTLS only.
    How much code are we talking about here?

    As far as I can tell, the difference would be to add about six lines of code to check that TLS had started before a MAIL, RCPT, or DATA command., and there's nothing to delete. Am I missing anything?
    --
    Regards,
    John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies",
    Please consider the environment before reading this e-mail. https://jl.ly
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Sat Sep 26 01:55:25 2026
    From Newsgroup: comp.mail.sendmail

    John Levine wrote:
    In today's skirmish, one of the TLS crowd says:

    1. [Current text] Requiring all email server developers to write code to accept unencrypted mail, even if none of their users wants it

    Viktor clearly explained again and again that this is completely
    bogus. The SMTP engine MUST handle cleartext - that's what it gets
    from the TLS layer.

    So my question is, imagine a hypothetical version of sendmail that was STARTLS only.
    How much code are we talking about here?

    None. It can already be enforced. See cf/README:

    Allowing Connections
    --- Synchronet 3.22a-Linux NewsLink 1.2