-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In message <[email protected]>, Vittorio <[email protected]> writes
>>> Header recipes declare voluntary modifications. An attacker injecting >>> a >>> forged X-Original-Sender will not declare it in a recipe. >> >> so I should hope... though I don't think the text for validation >> currently covers that. Perhaps it should >I agree, it should. the rest of the text shows that you misunderstood ... I was suggesting that providing a recipe for a header that you do not need to provide a recipe for should be a verification error >The specification currently generates a body recipe for every >modification to the message body, however minor. Yet the entire X-* >namespace, including headers that carry antispam scores, authenticated >user identities and original sender information, is excluded from >signing by design. An intermediary that adds a comma to the body must >declare it in a recipe. An intermediary that injects >X-Authenticated-User: [email protected] the only organisation that does that and has sent me mail this year (and I receive a LOT of email) is megamailservers.eu -- and they did not DKIM1 sign it (and I suspect they have not thought it through especially well since that piece of personal information is not at all the same as the identity in the From: header field) >generates no signal at all. This >proposal does not ask to sign all X-* headers. It asks the working group >to converge on a fixed subset of X-* headers related to spam >classification, virus scanning and delivery tracking that should be >included in the signed set. I don't see the WG responding to your invitation at present. - -- richard @ highwayman . com "Nothing seems the same Still you never see the change from day to day And no-one notices the customs slip away" -----BEGIN PGP SIGNATURE----- Version: PGPsdk version 1.7.1 iQA/AwUBaiLoc2HfC/FfW545EQJOjACfdtPrqLEFAEJ1PY+1ghvaD07yOmEAoN0x /fWWccbJ4a+gaY/wWMdkoI1W =Y35d -----END PGP SIGNATURE----- _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
