Hi!

I'd prefer to allow for different selectors. Even if we'd also allow for a selector to map for a key per algorithm, still we'd restrict DKIM2 users less if we let them decide if they "overload" one selector for multiple algorithms or they map the algorithms to different selectors.

I'd still prefer to have selector/algorithm/signature "bundled" (and hashes either bundled the same, or referenced from a separate body hash "array" as I suggested).

':' is probably a good separator here.

Hannah.

On 7/17/25 11:41, John Levine wrote:
It appears that Bron Gondwana  <[email protected]> said:
   Tags with duplicate names MUST NOT occur within a single tag-list; if
   a tag name does occur more than once, the entire tag-list is invalid.

So if we want to allow multiple b= keys, we would have to change this 
definition, which might
cause issues with existing libraries that were built on this invariant.

Or we could slice it the other way as I suggested a few messages back,

   ... s=sel1:sel2:sel3 a=alg1:alg2:alg3 b=hash1:hash2:hash3 ...

If we go with my proposal to allow a single selector to have multiple keys
with different algorithms, we could simplify it to

   ... s=sel a=alg1:alg2:alg3 b=hash1:hash2:hash3 ...

You can't have colons in base64 so that's in principle backward compatible with
the way we encode single signatures.

R's,
John
--
Hannah Stern            Mail System Development
www.mail-and-media.com  1&1 Mail & Media Development & Technology GmbH
[email protected]   Brauerstraße 48  76135 Karlsruhe  Germany
+49 721 91374-4519

Hauptsitz Montabaur, Amtsgericht Montabaur, HRB 5452

Geschäftsführer: Alexander Charles, Dr. Michael Hagenau, Dana Kraft,
Thomas Ludwig

Member of United Internet

Diese E-Mail kann vertrauliche und/oder gesetzlich geschützte
Informationen enthalten. Wenn Sie nicht der bestimmungsgemäße Adressat
sind oder diese E-Mail irrtümlich erhalten haben, unterrichten Sie
bitte den Absender und vernichten Sie diese E-Mail. Anderen als dem
bestimmungsgemäßen Adressaten ist untersagt, diese E-Mail zu speichern,
weiterzuleiten oder ihren Inhalt auf welche Weise auch immer zu verwenden.

This e-mail may contain confidential and/or privileged information. If you
are not the intended recipient of this e-mail, you are hereby notified
that saving, distribution or use of the content of this e-mail in any
way is prohibited. If you have received this e-mail in error, please
notify the sender and delete the e-mail.

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to