[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

msgtrk: MTQP, TLS, & SRV



There is currently a discussion going on in LDAPEXT about STARTTLS and
the interaction with SRV records that is probably of interest to MTQP.

I note that MTQP uses SRV records (or MX records) to find which host
to connect to, but I don't see any text on what name to expect once it
gets there.  This should probably be clarified.

It might also be nice to point out that, on multi-homed MTQP servers,
use of SRV records with the port specification can get around not
knowing what certificate to hand back.

Another possibility would be to add a "certificate expected" argument
to the STARTTLS command, allowing the server to choose which
certificate to return.  I believe there was discussion of this in a
working group meeting, but I don't recall what the outcome of it was.

Larry