-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
In message <[email protected]
il.com>, Wei Chuang <[email protected]> writes
>> > I propose that the specification or BCP should say that MTAs that
>> > need to forward such null recipe, "donotmodify" or "donotexplode"
>> > messages onwards for whatever reasons, should delete all prior
>> > DKIM2 headers and re-sign the DKIM2 signature as themselves. This
>> > probably means that the above language needs to be tweaked for
>> > this.
>>
>> That is not good advice for "donotexplode" !
>>
>
>So you'd be for the forensics approach. My worry, perhaps unfounded if
>everyone applies section 10.8, is that downstream receivers might
>misinterpret the earlier signatures.
you missed my point ... it is perfectly OK to forward "donotexplode"
email unless you know that it has been exploded (which you may not
unless a later hop reports that it has done so)
forwarding email that has been modified despite a "donotmodify" flag
will always be detectable and forwarding is very likely to end in tears
so if you must do so then yes, you are going to have to create an email
that is validly signed -- that might not involve discarding anything,
you could choose to wrap up the forwarded message in a MIME part and
send that along
- --
richard @ highwayman . com "Nothing seems the same
Still you never see the change from day to day
And no-one notices the customs slip away"
-----BEGIN PGP SIGNATURE-----
Version: PGPsdk version 1.7.1
iQA/AwUBagoYFWHfC/FfW545EQLlZQCg3GdC+cBtYGYmqqD/dG2hqCD2/LsAn1YV
rSey1q/+RaaOoIWxNm6GcMNK
=LLSv
-----END PGP SIGNATURE-----
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]