ietf-asrg
[Top] [All Lists]

Re: [Asrg] RFC5451 Re: who gets the report, was We really don't need

2010-02-10 11:23:08


-----Original Message-----
From: asrg-bounces(_at_)irtf(_dot_)org 
[mailto:asrg-bounces(_at_)irtf(_dot_)org] On Behalf Of
Alessandro Vesely
Sent: Wednesday, February 10, 2010 12:06 AM
To: asrg(_at_)irtf(_dot_)org
Subject: Re: [Asrg] RFC5451 Re: who gets the report, was We really
don't need

On 09/Feb/10 23:31, Murray S. Kucherawy wrote:
 Could the MDA add a DKIM signature for the authentication results
header?

 Yes, it could. However, removal of the field on forwarding would
then
 break the signature.

True, but you don't have to do that.

But retention is only allowed for trusted internal MTAs.

More accurately, removal is required if the A-R header claims to be one of 
yours but it's not coming from an MTA you trust (e.g. one of your border MXes).

An A-R header claiming to be from elsewhere doesn't have to be purged, so a 
signature covering it would continue to validate.  The MUA, however, is 
supposed to know to ignore those.
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>