On Thu, May 30, 2024 at 9:13 AM Alessandro Vesely <ves...@tana.it> wrote:

> z= saves all fields, which would be too much in most cases.  Moreover,
> doing so
> suggests treating all fields as a whole, rather than dealing with each
> one's
> peculiarity.
>

That's not what the RFC says.

Of course, if an Original- field is tampered with the original signature
> won't
> verify after replacing it, just like if you altered z=.  But then,
> reverting
> without cooperation is not the same as doing it with active opposition.
> Why
> would someone alter Original- fields?  A mediator wanting to disrupt the
> possibility to reverse had better removing the signature directly.
>

Space munging applied to all fields, for example, is enough to break this
scheme.  "z=", by contrast, is immune to such mutations, because it's
encoded.

-MSK
_______________________________________________
Ietf-dkim mailing list -- ietf-dkim@ietf.org
To unsubscribe send an email to ietf-dkim-le...@ietf.org

Reply via email to