ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Wrong Discussion - was Why mailing lists should strip DKIM signatures

2010-04-28 10:05:42

A few thoughts to fuel the discussion:

1) It may be that the BCP document would appropriately have a section
for end users of mail lists. One possible recommendation is that for
domains which have strong security concerns, they may want to have a
policy against posting to lists using the domain in question. (I'm
throwing this out as a straw man).

2) One possible recommendation to list managers is that if a message to
the list is DKIM signed AND has an ADSP discardable policy AND the
signature cannot be maintained intact then the list should bounce the
message.

3) Is there a way for us (perhaps in a future version) to provide for
some sort of "encapsulation" that will allow the original
signature/message to be maintained even as the list does certain (as yet
unspecified) actions which might currently break the signature? Just
blue skying here.

4) I recognize the chorus which says "mail lists have always done things
a certain way and who are you to tell us how or what we have to do".
Having given that recognition, in creating an authentication model it
seems self defeating not to provide mechanisms for the authentication to
survive things like maillists (for those maillists/software providers
willing to adopt whatever we come up with). Those lists which have
always done thigns a certain way and wish to continue could do so - no
harm no foul.

Mike

_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>