Proposal to Deprecate MAIL-FROM in Maintainer Object Database SIG APNIC 14, Kitakyushu, Japan 4 September 2002
Proposal Deprecate the MAIL-FROM authentication in APNIC Whois DB Affected MAIL-FROM objects replaced with CRYPT-PW generated by APNIC
Current Authentication NONE No protection MAIL-FROM E-mail Very weak protection CRYPT-PW Unix encrypted password PGP-KEY Public key algorithm protection http://www.ietf.org/rfc/rfc2725.txt
Motivation MAIL-FROM is not secure Stronger authentication now available PGP introduced with whois v3 MD5 soon available MAIL-FROM authentication deprecated in RIPE database http://www.ripe.net/ripe/mail-archives/db-wg/2002/msg00160.html
Objects Affected Current statistics MAIL-FROM: 183 Objects mntner: MAINT-AP-ISPNET descr: ISPNET Maintainer country: TH admin-c: JT12-AP tech-c: KO110-AP upd-to: admin@ispnet.com.th mnt-nfy: admin@ispnet.com.th auth: MAIL-FROM sysadmin@ispnet.com.th notify: admin@ispnet.com.th mnt-by: MAINT-AP-ISPNET referral-by: MAINT-AP-ISPNETADMIN changed: admin@ispnet.com.th 20020512 source: APNIC
Implementation Proposed Timeline 30 Sept 2002: Public announcement & mails to contacts of affected maintainers 30 Oct 2002: 1st reminders 30 Nov 2002: 2nd reminders 17 Dec 2002: cutover Affected MAIL-FROM objects replaced with CRYPT-PW generated by APNIC
Discussion Consensus from DB SIG to proceed with this proposal?