-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [answering this one topic at a time, mainly with a view to explaining where text in spec-04 has come from]
In message <[email protected]>, Hannah Stern <[email protected]> writes >> #1 introducing nd= as an alternative to mf= rt= for an imaginary hop. >> This is essemtially the "forward" signing scheme that Tobias suggested >Questions: > >- On verification, is it allowed that the latest signature (highest i) >has nd? I had not considered that in the text because the assumption was always that the two signatures (i=n; nd=; then i=n+1;mf=;rt=;) would be added at the same time. This need not be the case, but the entity adding the second signature is only going to do that where there an explicit (presumably contractual) agreement that they will do so. spec-04 will have some words on this >- Is it allowed to have more than one nd in a row? (I.e. i=4 has >nd=<domain of i=5>, i=5 has nd=<domain of i=6>)? if everything matches why not (though would be odd to do this) >- How is the mf/rt chain checked in the presence of nd? Just skip the nd >hop? I.e. if i=4 has mf/rt, i=5 has nd, i=6 has mf=rt, do I check i=6 >against i=4 using the usual rules? check the highest numbered DKIM2-Signature in the usual way (it will have the mf= rt=). As and when you check all the D-S header fields then check for alignment (an exact match of nd= and the d= of the next D-S header field in ascending order) - -- richard @ highwayman . com "Nothing seems the same Still you never see the change from day to day And no-one notices the customs slip away" -----BEGIN PGP SIGNATURE----- Version: PGPsdk version 1.7.1 iQA/AwUBakp0V2HfC/FfW545EQKl5ACg6VXwT0DXZbB6PASJ+AbXUH+N/QQAn21o VoMwi6av1yYt/Uev+/bpxRcs =Oian -----END PGP SIGNATURE----- _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
