Skip to content

Conversation

@blechschmidt
Copy link

Currently, the milter is not implemented in a downgrade-resistant manner. In particular, an attacker can induce SERVFAIL responses, e.g. by performing a DoS attack on the authoritative server for the _smimecert subdomain. This will cause outbound mail to remain unencrypted. It is therefore better to treat a SERVFAIL response like failed DNSSEC authentication.

Currently, the milter is not implemented in a downgrade-resistant manner. In particular, an attacker can induce SERVFAIL responses, e.g. by performing a DoS attack on the authoritative server for the _smimecert subdomain. This will cause outbound mail to remain unencrypted. It is therefore better to treat a SERVFAIL response like failed DNSSEC authentication.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant