-
Notifications
You must be signed in to change notification settings - Fork 23
Description
What 'provided bundle file' ? There has not been any mention of a bundle file, let alone seeing it 'provided' by anyone or anything.
Good grief, what a PITA this whole DANE thing is to set up. Am I to grasp that each time I generate a new cert (i.e. LetsEncrypt), I would also have to recreate the DANE records for the insanely complex DNS entries?
If so, this means that at/during every new DANE DNS records change, the mail is vulnerable to not being accepted because the DANE checks fail. Plus, more importantly; All this was to prevent what exactly? MITM attacks? This DNS propagation could take 48 hours, globally, until they are fully live. 48 hours in which the MITM attacks mitigation is null and void. What idiot designed this?
Because basically what you do is: Look for when the certs expire, find out how long DNS propagation takes, hope it takes long enough (or offer a non-propagated DNS to your victim for a MITM during SMTP auth) et voila. Useless.