ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Author Signature vs. Author Domain Signature / Internal vs External threats

2009-04-03 06:02:09
Dave,

First, this is one of the simplifications we get by the change that the 
working
group agreed to, with the RFC4871 Update about to be formally approved, and 
with
the use of SDID, rather than AUID, in ADSP:  the issue of a "parent" 
disappears.
   All that is left is the more general question of deciding how to 
distinguish
among outgoing mail streams with different SDID values.
   

If what you are saying is that the subdomain check is deprecated, that's 
fair.  But that doesn't mean the check is incompatible.

Second, either the d= matches the domain in the rfc5322.From field, or it
doesn't.  There is no complexity or subtlety to the test, so there are no
"implications" that need to be pointed out.

   

This is unresponsive to Jim's point.

Eliot

_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>