Conversation

Was mich am meisten verwundert, dass der Bund kein "ordentliches" Zertifikat für SMTP verwendet.
Quote Tweet
Weiß jemand, warum beim bund.de die #krypto config beim genaueren Hinsehen kaputt ist: * DNSSEC: ok * SMTP, 25/tcp: Zertifikat Root-CA nicht allgem. trusted * SMTP, 25/tcp: TLSA record: ok * bund.de (Port 443): TLSA record kaputt cc @BSI_Bund
4
2
Replying to and
There are pros and cons to ensuring a valid a cert from a public CA. The positives are: * A few brain-dead MTAs do opportunistic TLS wrong, they send in cleartext when TLS auth fails, instead of continuing anyway w/ STARTTLS. Given a valid cert they use TLS. ...
2
3
* You can, if you wish, publish an MTA-STS policy, and maintain associated DNS TXT records to enable some senders to use MTA-STS. The negatives are: * You have to rotate the certificate in time to keep it valid. * This can increase the odds of a mismatch with any DANE TLSA RRs.
2
2