cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: IanG <iang AT cacert.org>
- To: guillaume romagny <gr AT grhq.net>
- Cc: CAcert System Administrators <cacert-sysadm AT lists.cacert.org>
- Subject: Re: [Cacert-sysadm] CAcert email address snafu
- Date: Sat, 09 Aug 2008 18:50:13 +0200
- List-archive: <http://lists.cacert.org/pipermail/cacert-sysadm>
- List-id: CAcert System Admins discussion list <cacert-sysadm.lists.cacert.org>
guillaume romagny wrote:
Hi Ian,
it is just 450 temporary., it is expected to work 246 seconds later as mentioned.
It is working now ?
Yes, it is working now. However that is not the question. The comment below was entirely explanatory as to what would happen.
What I want to know is *why* and *what* and *where*???
The reason is this: The certificates that are issued by CAcert are *critically* dependent on email. If I can fiddle the mail, I can add any domain or email, and get a cert for it!
So, anything that happens to email is a concern. (To underscore this, note that DRC says that the email testing by CAcert is inadequate to audit, so the current situation must change.)
So, whatever is happening to email, we need some doco, some policy, some understanding. (And we need to fix the audit bugs.)
That's what I'm asking: what is going on, how much can we rely on email, who is poking around and greylisting and blacklisting and goldlisting and whatever... , and what does this do to the security model surrounding certificates?
iang
Kind regards,
Guillaume
IanG a écrit :
Huh? CAcert cannot send email to ... CAcert email addresses? Is this the "Tunix firewalling????"
=============
The mail server responsible for your domain indicated a temporary failure. This may be due to anti-SPAM measures, such as greylisting. Please try again in a few minutes.
450 iang AT cacert.org: recipient address temporarily rejected: greylisted for 246 seconds
=============
(I'm trying to add the domain to my account ... something that *could* be done automatically, as the authority for using that account is already within CAcert.)
iang
_______________________________________________
CAcert-sysadm mailing list
CAcert-sysadm AT lists.cacert.org
https://lists.cacert.org/cgi-bin/mailman/listinfo/cacert-sysadm
- [Cacert-sysadm] CAcert email address snafu, IanG, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, guillaume romagny, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Daniel Black, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/10/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Philipp Gühring, 08/10/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Guillaume ROMAGNY - CAcert support, 08/10/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Teus Hagen, 08/11/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/11/2008
- Re: [Cacert-sysadm] CAcert email address snafu, samj, 08/11/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/11/2008
- Re: [Cacert-sysadm] CAcert email address snafu, samj, 08/12/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/12/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Philipp Gühring, 08/10/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/10/2008
- Re: [Cacert-sysadm] CAcert email address snafu, Daniel Black, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, IanG, 08/09/2008
- Re: [Cacert-sysadm] CAcert email address snafu, guillaume romagny, 08/09/2008
Archive powered by MHonArc 2.6.16.