ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Re: WG Review: Domain Keys Identified Mail (dkim)

2005-12-22 12:21:39


'nowsp' canonicalization does not exist in "DKIMv2" (-base-01).  It was
eliminated, rather than deprecated, because it created a vulnerability.

sorry. i had misunderstood that line of discussion. and, yes, vulnerability counts as a showstopper.


While some -base-01 verifiers may implement legacy nowsp support, a
fully compliant -base-01 verifier may not work with a -base-00 signature
that uses nowsp canonicalization.

ack.

that still leaves useful over-the-wire compatibility, doesn't it?

d/

--

 Dave Crocker
 Brandenburg InternetWorking
 +1.408.246.8253
 dcrocker  a t ...
 WE'VE MOVED to:  www.bbiw.net

_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/ietf