DOI:  10.17487/RFC8617

The inclusion of the address headers in the signature, and possibly the 
Subject, is an issue:

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; 
s=arcselector9901; 
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=;

If a downstream server needs to modify either of these two values, the 
signature check fails.

It is my understanding that the Authenticated Received Check signature is to 
validate the chain of possession.  As such, in my opinion, the signature should 
only include immutable references.

In my opinion, there is value in NOT requiring headers to be stripped by 
downstream servers, thus maintaining the custody chain from origination to 
destination.

Thank you for your time and attention,

William M. Weist
Enterprise Architect I - Global Messaging - Mobile and Presence
CIO Team - End User Computing
[IQVIA logo_96dpi_100pxheight]
Learn more<http://www.iqvia.com/> about IQVIA(tm)

400 Campus Drive
Collegeville, PA 19426
USA

O: +1 610 244 2646 | M: +1 484 904 8244



________________________________________
IMPORTANT - PLEASE READ: This electronic message, including its attachments, is 
CONFIDENTIAL and may contain PROPRIETARY or LEGALLY PRIVILEGED or PROTECTED 
information and is intended for the authorized recipient of the sender. If you 
are not the intended recipient, you are hereby notified that any use, 
disclosure, copying, or distribution of this message or any of the information 
included in it is unauthorized and strictly prohibited. If you have received 
this message in error, please immediately notify the sender by reply e-mail and 
permanently delete this message and its attachments, along with any copies 
thereof, from all locations received (e.g., computer, mobile device, etc.). To 
the extent permitted by law, we may monitor electronic communications for the 
purposes of ensuring compliance with our legal and regulatory obligations and 
internal policies. We may also collect email traffic headers for analyzing 
patterns of network traffic and managing client relationships. For further 
information see: https://www.iqvia.com/about-us/privacy/privacy-policy. Thank 
you.
_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to