On 05/19/2015 13:01, Murray S. Kucherawy wrote:
On Tue, May 19, 2015 at 12:00 PM, Terry Zink
<[email protected] <mailto:[email protected]>>
wrote:
6.What is the proposed t= time limit? Is 30 seconds enough? Too
long? Too little?
I would guess too little, but at this point that's strictly a guess.
You need to leave enough time for possible network or other
transmission problems between the signer and the intermediary you're
trying to accommodate.
I expect you'll ultimately have to leave that up to the signer, no?
Traditional practice would set it sometime between hours and days. But
when somebody gets around to trying to exploit this window, sites with
quick (re-)delivery to most of their recipients will probably want to
cut the length of that exposure down...
--S.
_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc