SML Agenda

IETF 120 [hybrid] Vancouver

Tuesday, July 23rd, 2024
15:30 (Vancouver, UTC-7)/22:30 (UTC)
1.5 hours

Meetecho:
https://meetings.conf.meetecho.com/ietf120/?group=sml&short=&item=1
Notes: https://notes.ietf.org/notes-ietf-120-sml

Chair: Alexey Melnikov & Arnt Gulbrandsen

Notes Taker: Jim Fenton

Agenda

Daniel: Should the document talk about use of DKIM for validation of
authenticity?

Arnt: Also Authentication-Results header field?

DKG: end-to-end email encryption enthusiast: use the cryptographic
signatures and LAMPS Header Protection document. Can't always trust mail
servers.

Philip: clients and servers can be from different organizations, so
clients not trusting their servers is a consideration. Are concerns
about forwarding addressed in the documents?

Automated processing is a concern, dkg's cc case is an example.

Ben: what implementation do now is not necessarily what we want to
do in the future. For exampple the trusted sender concept.

Michael Slusarz: Are these problems specific to structured email? It
sounds like many of these are problems for email in general.

Ben: Think about "what is worse than HTML."

Pete: In html, we sandbox, etc. There are new contexts here that may
not have covered these issues as well.

Hans-Jörg: We are required to work on Trust/Security document by
charter.

Alexey: We have moral obligation to discuss this :-).

Mechanisms (encryption, trust)
Philip: Maybe some tradeoffs with encryption, like need to download
entire message.

Daniel: Already can send calendar invites, etc. Shouldn't invent
another encryption mechanism for this. (Alexey says we're not doing this
anyway).

DKG: Add a reference to LAMPS e2e encrypted email guidance draft
https://datatracker.ietf.org/doc/draft-ietf-lamps-e2e-mail-guidance/

Trent: per body part encryption, as some body parts might need more
protection than others

Jim: I am getting worried when "DKIM" and "trust" are used in the
same sentence. DKIM is limited in what it can achieve.

dkg: Pushing back on Trent per body part encryption proposal. See
discussion in LAMPS WG on why not, don't do it here.

Ran out of time to discuss this.