Skip to content

"We use the provided bundle file to.." #13

@jult

Description

@jult

What 'provided bundle file' ? There has not been any mention of a bundle file, let alone seeing it 'provided' by anyone or anything.

Good grief, what a PITA this whole DANE thing is to set up. Am I to grasp that each time I generate a new cert (i.e. LetsEncrypt), I would also have to recreate the DANE records for the insanely complex DNS entries?
If so, this means that at/during every new DANE DNS records change, the mail is vulnerable to not being accepted because the DANE checks fail. Plus, more importantly; All this was to prevent what exactly? MITM attacks? This DNS propagation could take 48 hours, globally, until they are fully live. 48 hours in which the MITM attacks mitigation is null and void. What idiot designed this?

Because basically what you do is: Look for when the certs expire, find out how long DNS propagation takes, hope it takes long enough (or offer a non-propagated DNS to your victim for a MITM during SMTP auth) et voila. Useless.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions