OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: ETRN too fast!
From: Robert A. Rosenberg (Bob.Rosenbergdigitscorp.com)
Date: Sun Oct 01 2000 - 22:06:02 CDT


At 01:10 +0200 on 09/30/2000, Brad Knowles wrote about Re: ETRN too fast!:

>I'd like to see the authentication behind something like ATRN, to
>make sure that it really is secure.

The RFC defines it as using AUTH (the same as allowing a user to
submit messages to you if not on your LAN).

You just need a table of Domains and UserIDs allowed to issue ATRNs
for them. The user issues AUTH to prove their identity. When ATRN is
issued, you look up the referenced entry (either by ID or Domain) to
see that there is authorization.