ietf-dkim
[Top] [All Lists]

[ietf-dkim] Re: New Issue: SSP Restrictive Policies Recommendationfor an RFC 4871 update

2008-01-03 08:49:33
Hector Santos wrote:

1. If a valid Originator Signature exists, the message is not
   Suspicious, and the algorithm terminates.
 
This means that the signature was verified via DKIM-BASE. It
also means the DKIM key record was obtained and all information
points to a 1st party signature.

Okay, I got it:  You are talking about cases with a signature
that turns out to be invalid (checking DKIM).  What I had in
mind was a missing (or garbage) signature, where the receiver
never checked DKIM.  Yes, for your cases it accelerates SSP.

In both cases, we short circuit the need to do a SSP discovery
by adding an optional DKIM-BASE SSP= tag option to DKIM-BASE
key records.

Now I don't see how "3rd party signature present" can accelerate
SSP for a missing 1st party signature, but that's no problem, I
only need to understand one case where your accelerator works ;-)

Thanks,

 Frank

_______________________________________________
NOTE WELL: This list operates according to
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>