Re: Publishing DKIM records with tinydns

DAve <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
John Levine wrote:
> Oh, my, we have a bunch of misconceptions here.  FYI, I am an active
> member of the DKIM committee, I sign all my outgoing mail with DKIM
> signatures, and serve the key records from djbdns.
> 
>>> Your record isn't valid because it's missing the string length byte.
> 
>> I don't understand, my djbdns install has no patches, the record is 
>> constructed as per the docs at http://cr.yp.to/djbdns
> 
> It's possible to publish TXT records using the tinydns generic syntax,
> if you put in the length bytes yourself, but there's no advantage to
> doing so.  The length bytes are mandatory.

OK. Your records worked, I was concerned that mine did not match yours 
when using the same dig from the same server. After reading Matthew's 
posts (yes I am certain my rebuild of tinydns-data was correct, I tested 
with a data.cdb with only the target domain) I re-investigated 
everything including reading the rfc and the online docs again.

> 
>> The key data is broken into two parts, so DKIM verification fails.
> 
> Ah.  Whatever you're using to do DKIM verification is broken.  The
> DKIM spec is quite clear, a verifier concatenates all of the strings
> in the TXT record, which it has to do since it's easy to create key
> records longer than 255 bytes.
> 
> I saw some early verifiers with the one-string bug but I thought
> they'd all been stamped out.  Please let us know what we're using so
> we can tell the author to fix it.

I was using dkim-test (at) altn (dot) com and the failure it reported 
was that the key was invalid, I did not keep the test message, I very 
much wish I had.

> 
> The Mail::DKIM perl module does a good job of generating and checking
> DKIM records.  Try using that.  I have a perl qmailqueue shim that
> adds signatures if anyone would like it.

That is what I was using, with a modified qmail-remote wrapper from Kyle 
Wheeler. SO... back to the part where I said "I think I am missing 
something here". I go back and rebuild everything since it seems that 
multipart responses *should* work.

First test it appears it does now work, at least the dkim-test (at) altn 
(dot) com test returns "dkim=pass header.d=pixelhammer.com 
(b=W1I3gMl1z5; 1:0:good);". So I dig to see where I went wrong and I see 
that my signing is incorrect causing the initial test failure. That 
failure seems to have caused me to see ghosts. I have three more test 
messages out to the tests listed at http://testing.dkim.org.

I will report success or failure when they return. I very much 
appreciate the help.

DAve

-- 
"Posterity, you will know how much it cost the present generation to
preserve your freedom.  I hope you will make good use of it.  If you
do not, I shall repent in heaven that ever I took half the pains to
preserve it." John Quincy Adams

http://appleseedinfo.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.