Qmail
[Top] [All Lists]

Re: Broken DomainKey .. or dead project?

To: qmail@list.cr.yp.to
Subject: Re: Broken DomainKey .. or dead project?
From: Phil <philsross@gmail.com>
Date: Wed, 4 Apr 2007 22:49:59 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=jWqXMVZ0l0G7noQodJ+5b/MBekNdMDNpxAmeZmgmQwdmSlVaV0FpYfHfv6omDLaBfJtXqXKP7neOLnHmEKc7I2O1VW19/bLghuu5V+aptYcEyYmsinq7e2vQT5puZ50YtERzF+iwAE6dfyb1vlZ4F+xh/YEAYvN0fFryXeVyxZY=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=msu4iQjSfiM+4zWRGTvuHlOVHkV+BP4iKqirP/SrTUJXvqHxjsGqQclk786Ucvt4u9Cd0X+WrsBsZlasAAmR7DSAgbrxKON/juWO8XW8q6wunb6lQHpFTVe/1HquYPkN65KLTYJIQNpJGKMRT39GHC2WXMi31ACww2YRwpllibI=
Domainkey-status: good (test mode)
In-reply-to: <20070404202452.GD22829@c-76-18-79-168.hsd1.nm.comcast.net>
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <b86db13f0704011331m4135c427vc934ced0d8b64120@mail.gmail.com> <20070401205313.GA5988@discworld.dyndns.org> <b86db13f0704011429x17f3e0b1w903861f725380af5@mail.gmail.com> <20070401225748.GA6359@discworld.dyndns.org> <1175514940.31108.92.camel@castor.taos-it.nl> <b86db13f0704041207p6b6c548ai617ff192c7d27414@mail.gmail.com> <p06240603c239aa94b54f@128.163.18.106> <20070404200344.GA20446@discworld.dyndns.org> <20070404202452.GD22829@c-76-18-79-168.hsd1.nm.comcast.net>
[..] A message can end up with multiple DK
signatures that way, but that's not a bad thing. If anything, it means
there's more verifiable information about the path of the email.
~Kyle

Have you seen qmail-dk sign a message that is already signed?  I don't
think qmail-dk can sign a message that already has a DK signature -
when I set it up to sign all messages that were being relayed through
my server, qmail-dk would sign and forward mail that didn't already
have a signature, but die with "554 mail server permanently rejected
message (#5.3.0)" for mail messages that already had a signature.
This was painful to detect and troubleshoot, because no trace of the
failure was left in any logs, I had to capture the offending messages
and manually play them back, with and without DK signatures to confirm
the problem.  Anyone else noticed this?

<Prev in Thread] Current Thread [Next in Thread>