Re: New "Old-" headers emerging from the horizon
Sam Varshavchik <[email protected]>
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Alessandro Vesely writes: > On Sun 28/Jan/2024 00:53:01 +0100 Sam Varshavchik wrote: >> Bernd Wurst writes: >>> Am 27.01.24 um 15:00 schrieb Sam Varshavchik: >>>> [...] >> >>> As long as a server does not have BIMI validation functionality or has no >>> MUA that trusts it, it seems to be completely irrelevant if those headers >>> are removed or not. >> >> Well, I'm not well versed in the intricacies of DKIM but the spec explicitly >> states that any existing headers need to be renamed but only after >> validating the DKIM signature. >> >> I guess what that means is that Courier will leave this alone and leave it >> up to the DKIM filter to munge the headers. > > > One can never tell what MUAs users are running, let alone whether their next > version is going to support BIMI. > > The best approach would be for Courier to Old- them, like A-R:s. None of > them should be DKIM signed. At any rate, filters know that "Old-" is added > by Courier, and in theory can remove it from the hash computation used to > verify the signature. What if there's already a set of Old- headers. The mail was forwarded and rebranded by some helpful middleman, and rebranded. Now there are multiple sets of Old- headers in the message, and nothing to indicate which one of them should be included in the signature verification. _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZbZZUQAKCRCKYPgoojZS 4iiIAQCBzPiieyMo3jHAh2KeJhaq8VpwBP2qZighV023vL4UDgD5ARi18cYFtx8r nUYO3fek5GrxYnMfsyqgEpa7UfDU3A8= =yY8w -----END PGP SIGNATURE-----