[Mailman-Developers] dkim-signature headers

Barry Warsaw barry at python.org
Thu Feb 8 19:35:31 CET 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Excellent post Steve, thanks.

I think we're converging on a solution for Mailman both in the short  
term and in the long term.  See my previously posted wiki link for my  
current thoughts on the matter.  I just wanted to add one other thing...

On Feb 8, 2007, at 12:41 AM, Stephen J. Turnbull wrote:

> "From == signing domain".  Just generalize that to include
> "List-Id == signing domain" in the policy agent software!  And
> "Sender == signing domain".

I definitely agree that "List-ID == signing domain" should be added  
for interoperability with mailing lists.  I'm not sure about Sender,  
only because Mailman's addition of Sender itself is not without some  
controversy (mostly over interpretation of RFC 2822 language IIRC).   
But there's no doubt that well-behaved mailing lists should include  
List-ID, so that makes a natural header to sign.  See my discussion  
in the wiki page for situations where we might /not/ want to sign  
List-ID though.

Michael, since you're a DKIM spec insider, can you please relay this  
discussion to that community (if you agree with us of course!).   
We're making a good faith effort to do our part, and I'd like to see  
the DKIM specs acknowledge the mailing list use case more strongly.

Thanks,
- -Barry

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)

iQCVAwUBRcttc3EjvBPtnXfVAQJXAAP+P9Ddon+VPGcu9JefS9gxWOVPuWJDNsWI
8r0l0DIxJ8AZysCLSVzXAXEJqTapQjWB8l7fGZQZjznPFjea6/L1jR9yVwZVqRYI
J5nbpq2m3OerNpKkBM6rUHpSXKVs8GrDwMyi+st626UwJW93muDeeNPU1DPoLxj7
6Kagg+VD5Ts=
=Nnuw
-----END PGP SIGNATURE-----


More information about the Mailman-Developers mailing list