Re: [exim] SNI and DANE TLSA record monitoring

Startseite
Nachricht löschen
Nachricht beantworten
Autor: Felipe Gasper
Datum:  
To: Jan Ingvoldstad
CC: exim users
Betreff: Re: [exim] SNI and DANE TLSA record monitoring

> On Oct 19, 2016, at 9:13 AM, Jan Ingvoldstad <frettled@???> wrote:
>
>> I’d be fine with some facility to configure by-domain configs, logs, or
>> what not in tandem with the certificate. Just as long as it’s still simple
>> and easy to determine the certificate by the DOMAIN, not by served content.
>>
>>
> Well, SMTP doesn't "serve content" per se, so I don't really get that
> objection.


Depends on your conception of “serve content”. Insofar as we might consider “content” as the entire application (matrix of inputs/outputs), Exim/SMTP does indeed “serve content”. Anyway, semantics.

>
> What I think, is that which certificate gets served, should be fully
> configurable based on the information available at the time you need to
> serve the certificate. That's not a lot of information. :)


Furious agreement. :)

-FG