Skip to content

Return TEMPFAIL upon SERVFAIL#6

Open
blechschmidt wants to merge 1 commit intosys4:masterfrom
blechschmidt:master
Open

Return TEMPFAIL upon SERVFAIL#6
blechschmidt wants to merge 1 commit intosys4:masterfrom
blechschmidt:master

Conversation

@blechschmidt
Copy link

Currently, the milter is not implemented in a downgrade-resistant manner. In particular, an attacker can induce SERVFAIL responses, e.g. by performing a DoS attack on the authoritative server for the _smimecert subdomain. This will cause outbound mail to remain unencrypted. It is therefore better to treat a SERVFAIL response like failed DNSSEC authentication.

Currently, the milter is not implemented in a downgrade-resistant manner. In particular, an attacker can induce SERVFAIL responses, e.g. by performing a DoS attack on the authoritative server for the _smimecert subdomain. This will cause outbound mail to remain unencrypted. It is therefore better to treat a SERVFAIL response like failed DNSSEC authentication.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant