ietf-mailsig
[Top] [All Lists]

Re: Better DKIM Verification Example Needed

2005-07-27 19:32:48

On July 27, 2005 at 15:26, Michael Thomas wrote:

IMO, it is much cleaner to have the signature in its own header
field so header field canonicalization is uniform across all
fields.

What happens if you have more than one signature? I don't see it as
any cleaner and in fact it looks like it adds complexity to me.

I'm assuming the complexity is associating the signature data
with the meta-info data.  If the header fields are the same
name, their proximity together determines what goes with what.
I believe Ned stated in the past that re-arranging of same-named
header fields does not happen, or is extremely rare.

Of course, it would be nicer to have different names, but I guess
this opens things up to field re-ordering problems (which I wonder
how often this happens).  To protect against it would require
some "tieing" tag to make the association, which may be considered
"ugly".

--ewh

<Prev in Thread] Current Thread [Next in Thread>