Client Auth certificates, threat or menace?

Liste des GroupesRevenir à cm sendmail 
Sujet : Client Auth certificates, threat or menace?
De : johnl (at) *nospam* taugh.com (John Levine)
Groupes : comp.mail.sendmail
Date : 20. May 2025, 17:35:01
Autres entêtes
Organisation : Taughannock Networks
Message-ID : <100iavl$13mj$1@gal.iecc.com>
User-Agent : trn 4.0-test77 (Sep 1, 2010)
Let's Encrypt issues the vast majority of signed TLS certificates these days.
They rececently said they will end the option to sign Client Authentication
certificates, and only do the more common Server Authentication.

By my understanding, the only place that a mail system uses Client
Authentication certs is that a submission client can present a cert
for SMTP AUTH rather than a username and a password. It's a niche
feature and the normal way to do it is for the mail system to set up
its own private CA and sign the users' certs, so it can just check
that it sees its signature.
encrypt.

This thread at Let's Encrypt claims that this will break sendmail because it
checks for the Client bit when it's sending mail.  That seems wrong but I
figure it wouldn't hurt to ask.

https://community.letsencrypt.org/t/do-not-remove-tls-client-auth-eku/237427

--
Regards,
John Levine, johnl@taugh.com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly

Date Sujet#  Auteur
20 May 25 * Client Auth certificates, threat or menace?8John Levine
20 May 25 `* Re: Client Auth certificates, threat or menace?7Claus Aßmann
20 May 25  `* Re: Client Auth certificates, threat or menace?6John Levine
21 May 25   `* Re: Client Auth certificates, threat or menace?5Claus Aßmann
22 May 25    +* Re: Client Auth certificates, threat or menace?2Claus Aßmann
22 May 25    i`- Re: Client Auth certificates, threat or menace?1John Levine
22 May 25    `* Re: Client Auth certificates, threat or menace?2John Levine
23 May 25     `- Re: Client Auth certificates, threat or menace?1Claus Aßmann

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal