Re: Generic records and DKIM
DAve <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
John Levine wrote:
>> In order to serve the DKIM key I created generic records with a record
>> type of 16 for TXT. When I test the server with dnsq everything looks
>> good. I almost pushed the changes live but decided to test with dig
>> first. I cannot seem to get dig to display any generic records.
>
> Your record isn't valid because it's missing the string length byte.
I don't understand, my djbdns install has no patches, the record is
constructed as per the docs at http://cr.yp.to/djbdns
> Don't try to use generic records. TXT records in tinydns start with a
> quote, e.g.
>
> 'k0903._domainkey.iecc.com.:v=DKIM1; h=sha1\072sha256; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN5YERrZdMCFcAnd8a83MN53tpAxL8SkMHWEf1oyg5AAnuI0aQXsxAysbaxEVHZQ5zlsxVWl1ZuHSkr1ysOp23yerLz9uKFwJXSZDt7ocVDuLt8cNuPoMCu0bk4HfvfVKhOJ/tjLDlf0Nqo/SB3p2DoPiH9KQnYKPypnBmU5ljBQIDAQAB ;
>
> Remember to escape any colons in the data as \072
I didn't use a text record because of the length. For example, my data
file now contains this after changing to a text record,
'default._domainkey.pixelhammer.com:v=DKIM1;
k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjdJZZv9dOJ6JL/gZp58dkt/a9ZGt2
ap051inDc9BG3UhwaU2VVrKX+XocHSS0OAQmQPtAFs2xUtJjNvs15mWaccuRIo3qB8GSJYJ+5ms3F2WfD50Mtjpb5pMVsmgkWl/lvPXGd16ddCvcIbGP84Qcv
tWq88DhUrCHl9ZdpiyS+wIDAQAB;:300
But when I dig that record I see this,
]# dig @10.0.241.66 default._domainkey.pixelhammer.com TXT +short
"v=DKIM1\;
k=rsa\;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDjdJZZv9dOJ6JL/gZp58dkt/a9ZGt2ap051inDc9BG3UhwaU2VVrKX+XocHSS0OAQmQPtAFs"
"2xUtJjNvs15mWaccuRIo3qB8GSJYJ+5ms3F2WfD50Mtjpb5pMVsmgkWl/lvPXGd16ddCvcIbGP84QcvtWq88DhUrCHl9ZdpiyS+wIDAQAB\;"
The key data is broken into two parts, so DKIM verification fails. Oddly
when I query your record, your key is intact.
# dig k0903._domainkey.iecc.com TXT +short
"v=DKIM1\; h=sha1:sha256\;
p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN5YERrZdMCFcAnd8a83MN53tpAxL8SkMHWEf1oyg5AAnuI0aQXsxAysbaxEVHZQ5zlsxVWl1ZuHSkr1ysOp23yerLz9uKFwJXSZDt7ocVDuLt8cNuPoMCu0bk4HfvfVKhOJ/tjLDlf0Nqo/SB3p2DoPiH9KQnYKPypnBmU5ljBQIDAQAB
\;"
Still there is something I am missing here that searching has not
provided. Using dnsq shows everything is working fine, dig fails on both
generic and text key records. I am not confident the records will work
to verify emails.
DAve
--
"Posterity, you will know how much it cost the present generation to
preserve your freedom. I hope you will make good use of it. If you
do not, I shall repent in heaven that ever I took half the pains to
preserve it." John Quincy Adams
http://appleseedinfo.org