Re: New "Old-" headers emerging from the horizon

Alessandro Vesely <[email protected]>
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
On Sun 28/Jan/2024 14:40:33 +0100 Sam Varshavchik wrote:
> Alessandro Vesely writes:
> 
>> On Sun 28/Jan/2024 00:53:01 +0100 Sam Varshavchik wrote:
>>> Bernd Wurst writes:
>>>> Am 27.01.24 um 15:00 schrieb Sam Varshavchik:
>>>>> [...]
>>>
>>>> As long as a server does not have BIMI validation functionality or has no 
>>>> MUA that trusts it, it seems to be completely irrelevant if those headers 
>>>> are removed or not.
>>>
>>> Well, I'm not well versed in the intricacies of DKIM but the spec explicitly 
>>> states that any existing headers need to be renamed but only after 
>>> validating the DKIM signature.
>>>
>>> I guess what that means is that Courier will leave this alone and leave it 
>>> up to the DKIM filter to munge the headers.
>>
>>
>> One can never tell what MUAs users are running, let alone whether their next 
>> version is going to support BIMI.
>>
>> The best approach would be for Courier to Old- them, like A-R:s.  None of 
>> them should be DKIM signed.  At any rate, filters know that "Old-" is added 
>> by Courier, and in theory can remove it from the hash computation used to 
>> verify the signature.
> 
> What if there's already a set of Old- headers. The mail was forwarded and 
> rebranded by some helpful middleman, and rebranded.
> 
> Now there are multiple sets of Old- headers in the message, and nothing to 
> indicate which one of them should be included in the signature verification.


Uh... if the order of header fields is intact, it should still be possible to 
identify which are the signed ones by the position where they appear.  Not a 
bullet proof procedure in any case.


Best
Ale
-- 










_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.