Qmail
[Top] [All Lists]

Re: Broken DomainKey .. or dead project?

To: qmail@list.cr.yp.to
Subject: Re: Broken DomainKey .. or dead project?
From: Matt Simpson <net-qmlist@jmatt.net>
Date: Wed, 4 Apr 2007 16:42:50 -0400
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=jmatt.net; b=W1NNSY/uN5P6q3zWwlb2YXgkz6jshPbG+2bLVO6cPXtF61iyQE/3PYzRI/p+DOunvLFKV1xbAgB5AezFXMTsr3UQnYYAKLRBwk5fOw+5c1Qombd2GFSMlYEK+/7qT4mXKw/66GzaQjpr0pJZj4aJSXd0xgKs5DFXQ+7XB9GUZvo=; h=Received:Mime-Version:Message-Id:In-Reply-To:References:Date:From:Subject:Mime-Version:Content-Type;
Domainkey-status: bad
In-reply-to: <20070404202452.GD22829@c-76-18-79-168.hsd1.nm.comcast.net>
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <b86db13f0704011331m4135c427vc934ced0d8b64120@mail.gmail.com> <20070401205313.GA5988@discworld.dyndns.org> <b86db13f0704011429x17f3e0b1w903861f725380af5@mail.gmail.com> <20070401225748.GA6359@discworld.dyndns.org> <1175514940.31108.92.camel@castor.taos-it.nl> <b86db13f0704041207p6b6c548ai617ff192c7d27414@mail.gmail.com> <p06240603c239aa94b54f@[128.163.18.106]> <20070404200344.GA20446@discworld.dyndns.org> <20070404202452.GD22829@c-76-18-79-168.hsd1.nm.comcast.net>
At 2:24 PM 4/4/07, Kyle Wheeler wrote:
The DK header itself tells you what domain to look up.

OK, so I was sort of half right. The verifier looks in the DK header to know what domain to look up. The signer is responsible for putting the domain in there. And when qmail-dk signs the message, it uses the domain in the Sender: or From: header

In the case of signing bounce messages, the domain to use would presumably the one in /var/qmail/control/me, since that's what appears in the From: header on bounces.

<Prev in Thread] Current Thread [Next in Thread>