Re: Publishing DKIM records with tinydns
DAve <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
John Levine wrote: > Oh, my, we have a bunch of misconceptions here. FYI, I am an active > member of the DKIM committee, I sign all my outgoing mail with DKIM > signatures, and serve the key records from djbdns. > >>> Your record isn't valid because it's missing the string length byte. > >> I don't understand, my djbdns install has no patches, the record is >> constructed as per the docs at http://cr.yp.to/djbdns > > It's possible to publish TXT records using the tinydns generic syntax, > if you put in the length bytes yourself, but there's no advantage to > doing so. The length bytes are mandatory. OK. Your records worked, I was concerned that mine did not match yours when using the same dig from the same server. After reading Matthew's posts (yes I am certain my rebuild of tinydns-data was correct, I tested with a data.cdb with only the target domain) I re-investigated everything including reading the rfc and the online docs again. > >> The key data is broken into two parts, so DKIM verification fails. > > Ah. Whatever you're using to do DKIM verification is broken. The > DKIM spec is quite clear, a verifier concatenates all of the strings > in the TXT record, which it has to do since it's easy to create key > records longer than 255 bytes. > > I saw some early verifiers with the one-string bug but I thought > they'd all been stamped out. Please let us know what we're using so > we can tell the author to fix it. I was using dkim-test (at) altn (dot) com and the failure it reported was that the key was invalid, I did not keep the test message, I very much wish I had. > > The Mail::DKIM perl module does a good job of generating and checking > DKIM records. Try using that. I have a perl qmailqueue shim that > adds signatures if anyone would like it. That is what I was using, with a modified qmail-remote wrapper from Kyle Wheeler. SO... back to the part where I said "I think I am missing something here". I go back and rebuild everything since it seems that multipart responses *should* work. First test it appears it does now work, at least the dkim-test (at) altn (dot) com test returns "dkim=pass header.d=pixelhammer.com (b=W1I3gMl1z5; 1:0:good);". So I dig to see where I went wrong and I see that my signing is incorrect causing the initial test failure. That failure seems to have caused me to see ghosts. I have three more test messages out to the tests listed at http://testing.dkim.org. I will report success or failure when they return. I very much appreciate the help. DAve -- "Posterity, you will know how much it cost the present generation to preserve your freedom. I hope you will make good use of it. If you do not, I shall repent in heaven that ever I took half the pains to preserve it." John Quincy Adams http://appleseedinfo.org