90 likes | 200 Views
Email Authentications. INBOX Authentication Panel San Jose, CA – 2004 Dave Crocker Brandenburg InternetWorking <http://brandenburg.com/current.html>. Security Functions for Email. Identities. Reference Semantic Peer MTA IP SMTP client EHLO Domain SMTP client
E N D
Email Authentications INBOX Authentication Panel San Jose, CA – 2004 Dave Crocker Brandenburg InternetWorking <http://brandenburg.com/current.html>
Security Functions for Email D. Crocker INBOX / Authentication – SJ,2004
Identities Reference Semantic Peer MTA IPSMTP client EHLO DomainSMTP client Provider IPSMTP client site Mail-FromBounces address FromAuthor SenderPosting agent ReceivedHandling sites D. Crocker INBOX / Authentication – SJ,2004
Object Channel Secure Secure Secure Secure MTA MTA MTA MTA MTA MTA MTA Secure MTA Secure MTA MTA Secure Secure MTA MTA MTA MTA Secure Mail Secure Mail Mail Mail Mail Mail Security Models Mail Mail D. Crocker INBOX / Authentication – SJ,2004
The Path in a Kinder, Simpler World MSA MTA MUA PeerMTA Mail Agents MUA = User MSA = Submission MTA = Transfer MDA = Delivery MTA MDA MUA D. Crocker INBOX / Authentication – SJ,2004
MTA Path(s) Today MSA MTA MTA MTA PeerMTA MUA MTA MTA MTA PeerMTA MTA MTA MTA MTA MDA MUA D. Crocker INBOX / Authentication – SJ,2004
MTA SMTP 2821.MailFrom Reg Assigns MailFrom (bounce address) oMUA MSA MTA1 Did MSA authorize MTA1to send this message? MTA2 Did MSA authorize MTA2 to send this message? PeerMTA • Authority and Accreditation of MSA and MSA domain administrators • MSA must pre-register and trust each MTA in path MTA3 Did MSA authorize MTA3to send this message? PeerMTA MTA4 MDA rMUA D. Crocker INBOX / Authentication – SJ,2004
MTA SMTP RFC2821.HELO Reg oMUA MSA MTA1 Did administrator of domain asserted by MTA1 authorize it to be an MTA? MTA2 PeerMTA Did administrator of domain asserted by MTA2 authorize it to be an MTA? MTA3 PeerMTA Did administrator of domain asserted by MTA3 authorize it to be an MTA? • Authority/Accreditation of Domain Administrator • Trust of latest-hop network operation MTA4 MDA rMUA D. Crocker INBOX / Authentication – SJ,2004