SMTP Strict Transport Security
SMTP Strict Transport Security
Posted Apr 22, 2016 2:59 UTC (Fri) by neilbrown (subscriber, #359)In reply to: SMTP Strict Transport Security by raven667
Parent article: SMTP Strict Transport Security
The client must have made a deliberate choice to use SMTPS rather than SMTP.
I don't see how that it different to a deliberate choice to abort a connection if STARTTLS isn't offered, or fails.
I don't see how that it different to a deliberate choice to abort a connection if STARTTLS isn't offered, or fails.
Both ends of the connection can choose which levels of security are acceptable. A MITM attacker can always force the connection to use the lowest mutually acceptable level. The particular details of the negotiation are only of interest to implementers.
