Re: A permission to re-sign header

Pete Resnick <[email protected]> Fri, 18 Apr 2014 13:32:07 -0500
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
First of all, "permission to re-sign" seems to me to be the wrong 
semantics. This is simply "originally sent from here to there". The 
originating site (example.com) wants to say, "This message came from 
example.com and got sent to [email protected]", in a way that 
someone who receives a message from foo.example.net can check.

On 4/17/14 9:19 PM, John Levine wrote:
> As I understand it, the original sender puts a hard to forge single
> use token in the message, which the forwarder can include in the
> signed message.
>    

It could be hard to forge, or it could be hard for anyone else to read 
(e.g., the token could be encrypted to the forwarder and rewritten 
usefully by the forwarder). That is, what the list gets from the 
originator does not need to be exactly what the list sends to the 
eventual recipients. But either might be a reasonable approach.

> IF there is a M-R header with f= that matches the From: line address,
>
> AND the M-R header is included in a DKIM signature that is signed with
> d= that matches the M-R r=
>
> AND the M-R signature validates using the s= selector and f= domain
>
> AND the t= isn't too old (for some meaning of too old)
>
> THEN the message is considered to be aligned.
>
> Is that the general idea?
>    

Yep.

pr

-- 
Pete Resnick<http://www.qualcomm.com/~presnick/>
Qualcomm Technologies, Inc. - +1 (858)651-4478

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822