Skip to content

TLS-RPT#315

Draft
gunnim wants to merge 1 commit intosecurity-alliance:developfrom
gunnim:feat/tls-rpt
Draft

TLS-RPT#315
gunnim wants to merge 1 commit intosecurity-alliance:developfrom
gunnim:feat/tls-rpt

Conversation

@gunnim
Copy link
Contributor

@gunnim gunnim commented Dec 14, 2025

Added section on TLS-RPT

@Raiders0786

@vercel
Copy link

vercel bot commented Dec 14, 2025

Someone is attempting to deploy a commit to the Security Alliance Team on Vercel.

A member of the Team first needs to authorize it.

@gunnim gunnim changed the title tls-rpt TLS-RPT Dec 14, 2025
@scode2277
Copy link
Collaborator

Thanks also for this contribution @gunnim ;)!

As said in the PR about More context and instructions for DNSSEC and CAA sections, while the steward of the Domain and DNS Security, @Raiders0786, reviews the content added, I need to ask you to follow this guide about how to sign unverified commits as this PR can't be merged if all the commits are not verified. The guide assumes that the user following it has a signing key.

Thanks again:)

@gunnim gunnim force-pushed the feat/tls-rpt branch 2 times, most recently from c98122f to 72b713c Compare December 16, 2025 18:59
@vercel
Copy link

vercel bot commented Dec 17, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
frameworks Ready Ready Preview, Comment Dec 17, 2025 11:29am

@scode2277 scode2277 added the content:add This issue or PR adds content or suggests to label Dec 17, 2025
@Raiders0786
Copy link
Collaborator

i've commented feedbacks and changes above—are you able to see them @gunnim ?

@scode2277
Copy link
Collaborator

Can't see the comments here too @Raiders0786

@Raiders0786
Copy link
Collaborator

not sure what's the problem, i can see the comments on my end..

i commented this on Line 197:


Hey, solid work on this @gunnim!

The MTA-STS → TLS-RPT flow is accurate, and I especially like the RFC8460 citation addressing the report delivery concern.

Quick notes:

Should we also consider adding a note about max_age tuning during testing vs. production?
Might be worth mentioning MX record alignment with policy
The example could clarify that fallback only happens in testing mode, as if deployed on enforce mode = hard fail
Optional but nice to have: verification commands (dig, curl) and mention of report parsing tools since
TLS-RPT comes as JSON.

Overall, this is useful and technically correct - it just needs minor polish.
Good stuff, thanks for the contributions 👍

@mattaereal
Copy link
Collaborator

I still don't see any comment made by Raider's in the latest PRs, not by email nor by github. Can you show me where you made them @Raiders0786? I want to understand what's going on. Are you sure you're not replying via email directly to the author instead of directly in the thread?

@mattaereal mattaereal marked this pull request as draft January 22, 2026 16:11
@Raiders0786
Copy link
Collaborator

here you go.. it says "pending" is that the reason? Not sure why it shows like that thou @mattaereal

image

- All MX servers must support TLS with valid certificates
- Monitor policy file availability - if unreachable, mail delivery may fail in enforce mode

#### TLS-RPT
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey, solid work on this @gunnim!

The MTA-STS → TLS-RPT flow is accurate, and I especially like the RFC8460 citation addressing the report delivery concern.

Quick notes:

  1. Should we also consider adding a note about max_age tuning during testing vs. production?
  2. Might be worth mentioning MX record alignment with policy
  3. The example could clarify that fallback only happens in testing mode, as if deployed on enforce mode = hard fail

Optional but nice to have: verification commands (dig, curl) and mention of report parsing tools since
TLS-RPT comes as JSON.

Overall, this is useful and technically correct - it just needs minor polish.
Good stuff, thanks for the contributions 👍

@Raiders0786
Copy link
Collaborator

Previously it didn't used to show "submit review" ig now once i'm added to the frameworks i'm able to comment and submit the review properly it seems

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content:add This issue or PR adds content or suggests to

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

4 participants