-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[answering this one topic at a time, mainly with a view to explaining
where text in spec-04 has come from]

In message <[email protected]>, Hannah Stern
<[email protected]> writes

>> #1  introducing nd= as an alternative to mf= rt= for an imaginary hop.
>> This is essemtially the "forward" signing scheme that Tobias suggested
>Questions:
>
>- On verification, is it allowed that the latest signature (highest i) 
>has nd?

I had not considered that in the text because the assumption was always
that the two signatures (i=n; nd=; then i=n+1;mf=;rt=;) would be added
at the same time. This need not be the case, but the entity adding the
second signature is only going to do that where there an explicit
(presumably contractual) agreement that they will do so.

spec-04 will have some words on this

>- Is it allowed to have more than one nd in a row? (I.e. i=4 has 
>nd=<domain of i=5>, i=5 has nd=<domain of i=6>)?

if everything matches why not (though would be odd to do this)

>- How is the mf/rt chain checked in the presence of nd? Just skip the nd 
>hop? I.e. if i=4 has mf/rt, i=5 has nd, i=6 has mf=rt, do I check i=6 
>against i=4 using the usual rules?

check the highest numbered DKIM2-Signature in the usual way (it will
have the mf= rt=). As and when you check all the D-S header fields then
check for alignment (an exact match of nd= and the d= of the next D-S
header field in ascending order)

- -- 
richard @ highwayman . com                       "Nothing seems the same
                          Still you never see the change from day to day
                                And no-one notices the customs slip away"

-----BEGIN PGP SIGNATURE-----
Version: PGPsdk version 1.7.1

iQA/AwUBakp0V2HfC/FfW545EQKl5ACg6VXwT0DXZbB6PASJ+AbXUH+N/QQAn21o
VoMwi6av1yYt/Uev+/bpxRcs
=Oian
-----END PGP SIGNATURE-----

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to