Re: [ietf-dkim] The problem with the DKIM design community

2013-07-01 Thread Murray S. Kucherawy
On Sun, Jun 30, 2013 at 9:21 AM, John R. Levine wrote: > What I'm asking for is nothing like SES. I want the signature to be >> based on the envelope MAIL FROM:, but it is still the body that gets >> signed. No VERPing is called for. ... >> > > Where can we read the draft? > > +1. I pledge ope

Re: [ietf-dkim] The problem with the DKIM design community

2013-07-01 Thread Michael Deutschmann
On Mon, 1 Jul 2013, Alessandro Vesely wrote: > Well, not really. MAIL FROM: is only visible after delivery, so to > avoid dangling signatures one should store its value in some other > header field or... in the i= tag. ITYM "only visible *before* delivery" There's long been a standard header for

Re: [ietf-dkim] The problem with the DKIM design community

2013-07-01 Thread Alessandro Vesely
On Sun 30/Jun/2013 15:21:29 +0200 Michael Deutschmann wrote: > > "EDSP" would only pay attention to signatures where the "d=" matches > the right hand side of the RFC821 MAIL FROM:. > > This means that someone can publish the strictest possible EDSP > without causing mailing list false positives.