Re: Publishing DKIM records with tinydns

DAve <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
DAve wrote:
> John Levine wrote:
>> Oh, my, we have a bunch of misconceptions here.  FYI, I am an active
>> member of the DKIM committee, I sign all my outgoing mail with DKIM
>> signatures, and serve the key records from djbdns.
>>
>>>> Your record isn't valid because it's missing the string length byte.
>>
>>> I don't understand, my djbdns install has no patches, the record is 
>>> constructed as per the docs at http://cr.yp.to/djbdns
>>
>> It's possible to publish TXT records using the tinydns generic syntax,
>> if you put in the length bytes yourself, but there's no advantage to
>> doing so.  The length bytes are mandatory.
> 
> OK. Your records worked, I was concerned that mine did not match yours 
> when using the same dig from the same server. After reading Matthew's 
> posts (yes I am certain my rebuild of tinydns-data was correct, I tested 
> with a data.cdb with only the target domain) I re-investigated 
> everything including reading the rfc and the online docs again.
> 
>>
>>> The key data is broken into two parts, so DKIM verification fails.
>>
>> Ah.  Whatever you're using to do DKIM verification is broken.  The
>> DKIM spec is quite clear, a verifier concatenates all of the strings
>> in the TXT record, which it has to do since it's easy to create key
>> records longer than 255 bytes.
>>
>> I saw some early verifiers with the one-string bug but I thought
>> they'd all been stamped out.  Please let us know what we're using so
>> we can tell the author to fix it.
> 
> I was using dkim-test (at) altn (dot) com and the failure it reported 
> was that the key was invalid, I did not keep the test message, I very 
> much wish I had.
> 
>>
>> The Mail::DKIM perl module does a good job of generating and checking
>> DKIM records.  Try using that.  I have a perl qmailqueue shim that
>> adds signatures if anyone would like it.
> 
> That is what I was using, with a modified qmail-remote wrapper from Kyle 
> Wheeler. SO... back to the part where I said "I think I am missing 
> something here". I go back and rebuild everything since it seems that 
> multipart responses *should* work.
> 
> First test it appears it does now work, at least the dkim-test (at) altn 
> (dot) com test returns "dkim=pass header.d=pixelhammer.com 
> (b=W1I3gMl1z5; 1:0:good);". So I dig to see where I went wrong and I see 
> that my signing is incorrect causing the initial test failure. That 
> failure seems to have caused me to see ghosts. I have three more test 
> messages out to the tests listed at http://testing.dkim.org.
> 
> I will report success or failure when they return. I very much 
> appreciate the help.
> 
> DAve
> 

 From [email protected]
Authentication System:       DomainKeys Identified Mail
    Result:                   DKIM signature confirmed GOOD
    Description:              Signature verified, message arrived intact
    Reporting host:           sendmail.net

Authentication System:       Domain Keys
    Result:                   DK signature confirmed GOOD
    Description:              Signature verified, message arrived intact
    Reporting host:           sendmail.net


 From [email protected]
dkim=pass header.d=pixelhammer.com (b=VAPmQS9egC; 1:0:good);

So it looks like my text records are correct and everything is working 
with regards to tinydns. The issue appears to have been my original key 
data was incorrect, and my trouble shooting was flawed.

Thanks everyone for the assistance.

DAve

-- 
"Posterity, you will know how much it cost the present generation to
preserve your freedom.  I hope you will make good use of it.  If you
do not, I shall repent in heaven that ever I took half the pains to
preserve it." John Quincy Adams

http://appleseedinfo.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.