It appears that Tobias Herkula <[email protected]> said: >The draft appears to assume that the trust chain starts at the originator, >which intuitively seems like the cleaner model to me. However, I >could also imagine deployments where the first DKIM2-capable MTA attempts to >introduce an existing message into the DKIM2 ecosystem.
Some people I know have proposed a 0th link from a DKIM1 signature. Technically that's possible, if you unwind all the DKIM2 changes it should verify, and it might be help with the transition from DKIM1 to DKIM2, e.g., DKIM2 aware mailing lists could mutate and forward DKIM1 signed messages. But, of course, there's is nothing so long lived as a temporary software hack so we might just want to say if you want your mail to work well, get with the program and upgrade your DKIM software. R's, John _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
