Re: A permission to re-sign header
"John R Levine" <[email protected]> 18 Apr 2014 11:44:00 -0400
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
>> This is a permission to re-sign for a message From: >> [email protected], to be re-signed by a mailing list at ietf.org. The >> s= and a= and t= are the same as DKIM, the b= is a signature of a hash >> of the M-R header, similar to the b= signature in a DKIM-Signature. >> [...] > > Could the same thing be accomplished by a slight adjustment to VBR, > allowing a zone to vouch for another with the specific meaning that this > means X is authorized to generate mail for Y as long as X signs it? VBR is just a hint saying go look at a whitelist. It has no inherent security and only works because it assumes the receiver already knows what whitelists it trusts. (This must be obscure, too many people told us VBR was stupid because anyone could build a fake whitelist and point VBR headers at it.) Do you mean that every DMARC publisher would have its own exception whitelist, and the adjustment would be to assume the whitelist is credible if its name matches the From: domain? I suppose that could work, although expecting every domain to publish its own whitelist seems unlikely to scale. A domain could indirectly use someone else's domain whitelist via DNAME, but urrghh. If we expect there to be a handful of widely used DMARC exception whitelists, a mailing list could certainly use VBR as defined to point at the whitelist(s) in which its signing domain is included. Regards, John Levine, [email protected], Taughannock Networks, Trumansburg NY Please consider the environment before reading this e-mail. _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822
smime.p7s
(application/pkcs7-signature, 2.2 KB) - not displayed