Search the web
Sign In
New User? Sign Up
dkim-testers · DKIM Testers
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 1 - 30 of 69   Newest  |  < Newer  |  Older >  |  Oldest
Messages: Show Message Summaries   (Group by Topic) Sort by Date v  
#30 From: "Phil Wallisch" <philwallisch@...>
Date: Mon Mar 3, 2008 4:16 pm
Subject: Re: Re: DKIM Failures
pwallisc
Offline Offline
Send Email Send Email
 
Jim I've sent you samples off-list.  I've tried one other reflector and got the same results. 

On Fri, Feb 29, 2008 at 12:11 AM, Jim Fenton <fenton@...> wrote:

--- In dkim-testers@yahoogroups.com, "Phil Wallisch"
<philwallisch@...> wrote:
>
> Hello. I have DKIM signing enabled on my Secure Computing Ironmail
> appliance. When sending test messages to the dkim.org reflector I get
> mixed results. When I send from my Mac/Entourage client the DKIM
> passes every time. When I send from my Windows/Outlook client the
> DKIM fails every time. The MUAs go through the same set of MTAs. Any
> advice?
>

I have a hunch this is a canonicalization problem. Have you tried
other reflectors? Can you try sending me a message directly, off-list?

-Jim



#29 From: "Rene Lares" <laresuco@...>
Date: Fri Feb 29, 2008 5:47 pm
Subject: Problems with test result - Reflector dkim-test@...
laresuco
Offline Offline
Send Email Send Email
 
I trying to implement DKIM within our email service. I'm receiving the
result from the reflector: [DKIM-Sig: Warning] Null Signature.

I try to modify several things but I keep getting this error.

/* Original EMail */

DKIM-Signature: v=1; a=rsa-sha256; d=tralix.com; s=testdkim;
  c=simple/relaxed; q=dns/txt; i=testdkim@...;
  h=date:from:reply-to:to:subject:sender:mime-version:content-type;
bh=fawza4N9pXolelxo+qMpw8lARdcBchY4PennmJ0BHKw=;
b=iulWRcgDbr9FQgMX0seQYgkUzMOH0IrLrNDUN5NPO18M11s1PK92dFj370NqrF1n5N4jn4CNC6TtAj\
ekwwt2CjYL/dcz7d4Fl+7/8pA9YFjRRMeQ/eTZ04lVQUtlC4guKvn4rN3Ni6yMFAfDv0GMDfFzhPx6Mu\
k2uXzHQ2qNuFo=
Message-ID: <1.23.1.1.25@...>
Date: 29 feb 2008 11:32:08 -0000
From: <lares@...>
Reply-to: DKIM Test <lares@...>
Errors-To: <lares@...>
X-Mailer: TRALiX [Tralix Delivery 5.0.2.105]
X-EAuthentix: aa05e5d3d77c4d0886754f8511b04475
X-Tralix-Manifesto: #
To: <dkim-test@...>
Subject: Test DKIM
Sender: <lares@...>
Mime-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit

Este es un correo de prueba para verificar el correcto funcionamiento
del Delivery al momento
de firmar un correo con DKIM.

Atte.
Rene Lares.

/* End original EMail */

Any ideas why I get this error?

Thanks.

#28 From: Jim Fenton <fenton@...>
Date: Fri Feb 29, 2008 5:20 am
Subject: Signature failures using DomainKeys selectors
jim_fenton
Offline Offline
Send Email Send Email
 
I have been noticing quite a few signature failures lately  due to the
g= value on the key not matching the local-part of the i= value in the
signature.  This appears to be due to the common use of key records
(selectors) by signers applying both DomainKeys and DKIM signatures.
While the selectors are designed to be compatible, the example given in
the DomainKeys specification (RFC 4870) section 3.2.3 is NOT compatible
with DKIM.

The example, which looks like:

    brisbane._domainkey IN TXT "g=; k=rsa; p=MHww ... IDAQAB"

begins with g=;.  To DomainKeys, this means "match any address in the
domain".  To DKIM, it means "match no address in the domain" (match any
address would be g=*; ).

I strongly suggest that DK or DKIM key records not include the g=
tag/value unless they want to restrict a key to a specific
signing-address local-part, since the default values in both cases are
correct for unrestricted keys.

-Jim

#27 From: "Jim Fenton" <fenton@...>
Date: Fri Feb 29, 2008 5:11 am
Subject: Re: DKIM Failures
jim_fenton
Offline Offline
Send Email Send Email
 
--- In dkim-testers@yahoogroups.com, "Phil Wallisch"
<philwallisch@...> wrote:
>
> Hello.  I have DKIM signing enabled on my Secure Computing Ironmail
> appliance.  When sending test messages to the dkim.org reflector I get
> mixed results.  When I send from my Mac/Entourage client the DKIM
> passes every time.  When I send from my Windows/Outlook client the
> DKIM fails every time.  The MUAs go through the same set of MTAs.  Any
> advice?
>

I have a hunch this is a canonicalization problem.  Have you tried
other reflectors?  Can you try sending me a message directly, off-list?

-Jim

#26 From: "Phil Wallisch" <philwallisch@...>
Date: Tue Feb 26, 2008 9:52 pm
Subject: DKIM Failures
pwallisc
Offline Offline
Send Email Send Email
 
Hello.  I have DKIM signing enabled on my Secure Computing Ironmail
appliance.  When sending test messages to the dkim.org reflector I get
mixed results.  When I send from my Mac/Entourage client the DKIM
passes every time.  When I send from my Windows/Outlook client the
DKIM fails every time.  The MUAs go through the same set of MTAs.  Any
advice?

#25 From: Juan Altmayer Pizzorno <juan@...>
Date: Wed Apr 25, 2007 12:43 am
Subject: check-auth@...
jaltmayerpiz...
Offline Offline
Send Email Send Email
 
I've just pushed out a new version that adds canonicalization tracing and
also fixes an issue verifying 'relaxed' headers if the signature is followed
by a semicolon.

.. Juan

#24 From: Juan Altmayer Pizzorno <juan@...>
Date: Tue Apr 24, 2007 5:41 pm
Subject: Re: [dkim-dev] check-auth@...
jaltmayerpiz...
Offline Offline
Send Email Send Email
 
Hi Dave,

>  Should <http://testing.dkim.org/reflector.html> be updated, to uhhh, errrr,
>  reflect the current level of the specification that is supported by the
>  various reflectors?

Please add ours to the list.  We support the -10 ietf draft only.

.. Juan

#23 From: Arvel Hathcock <arvel.hathcock@...>
Date: Tue Apr 24, 2007 2:39 am
Subject: Re: [dkim-dev] check-auth@...
arvel.hathcock@...
Send Email Send Email
 
> Should <http://testing.dkim.org/reflector.html> be updated, to uhhh,
errrr, reflect
  > the current level of the specification that is supported by the
various reflectors?

Right now, our reflector is verifying allman-01 and ietf-0.5.  We will
be changing to ietf-1.0 ASAP!

--
Arvel Hathcock
CEO, Alt-N Technologies
http://www.altn.com

#22 From: Arvel Hathcock <arvel.hathcock@...>
Date: Mon Apr 23, 2007 11:46 pm
Subject: Re: [dkim-dev] check-auth@...
arvel.hathcock@...
Send Email Send Email
 
Juan, your verifier works with our signatures without any problems (so far).

And I must say that the report returned from your reflector is very
impressive and useful.  Puts ours to shame really.  Good job!

--
Arvel Hathcock
CEO, Alt-N Technologies
http://www.altn.com



Juan Altmayer Pizzorno wrote:
> I thought I'd let you know that our reflector now does DKIM verification.
> The update was actually done quite a while back, but we didn't make an
> announcement, so...
>
> .. Juan
> _______________________________________________
> dkim-dev mailing list
> dkim-dev@...
> http://mipassoc.org/mailman/listinfo/dkim-dev
>

#21 From: Juan Altmayer Pizzorno <juan@...>
Date: Mon Apr 23, 2007 5:18 pm
Subject: check-auth@...
jaltmayerpiz...
Offline Offline
Send Email Send Email
 
I thought I'd let you know that our reflector now does DKIM verification.
The update was actually done quite a while back, but we didn't make an
announcement, so...

.. Juan

#20 From: "Carlos Garcia Test" <carlos@...>
Date: Wed Feb 7, 2007 5:06 pm
Subject: Re: DKIM signature with QMAIL MTA
soyelcarlos2002
Offline Offline
Send Email Send Email
 
I have tried with three methods: nowsp, simple and relaxed  and the out it's the same
 
with noswp: DKIM-Status: Canonicalization type nowsp is no longer valid (This signature appears to be from an older draft of the standard)
with simple and relaxed: DKIM-Status: Canonicalization is no longer valid (This signature appears to be from an older draft of the standard)
 
:((
 
Thanks again
 
----- Original Message -----
From: Jason Long
Sent: Wednesday, February 07, 2007 2:45 PM
Subject: Re: [dkim-testers] DKIM signature with QMAIL MTA

>>>> "Carlos Garcia Test" <carlos@test.f-integra.org> 2/7/07 3:09 AM >>>
>Hello,
>
>I am trying to integrate DKIM signature with QMAIL MTA. I canīt belive that DKIM is integrated with sendmail, postfix and other and not with QMAIL.
>
>I use dkimproy (dkimproxyout.pl) and it hardly works... The email is signed but in the test it appears this:
>
>DKIM-Status: Canonicalization type nowsp is no longer valid (This signature appears to be from an older draft of the standard)
>
>DKIMPROXY uses DKIM version draft-01
>
>Can anybody help me?
>
>Thanks and sorry for my bad english.

Questions about dkimproxy should be sent to me directly (jason@...
or jlong@messiah.edu).

In this case, you are using dkimproxy with the nowsp canonicalization,
which apparently is not supported by the testing service you're using.
You should change your dkimproxy startup file to specify the
--method=relaxed argument.

E.g.
dkimproxy.out --method=relaxed ....

Jason


No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.411 / Virus Database: 268.17.29/673 - Release Date: 06/02/2007

#19 From: Jason Long <jason@...>
Date: Wed Feb 7, 2007 1:45 pm
Subject: Re: DKIM signature with QMAIL MTA
jason_long_name
Offline Offline
Send Email Send Email
 
>>>> "Carlos Garcia Test" <carlos@...> 2/7/07 3:09 AM >>>
>Hello,
>
>I am trying to integrate DKIM signature with QMAIL MTA. I canīt belive that
DKIM is integrated with sendmail, postfix and other and not with QMAIL.
>
>I use dkimproy (dkimproxyout.pl) and it hardly works... The email is signed but
in the test it appears this:
>
>DKIM-Status: Canonicalization type nowsp is no longer valid (This signature
appears to be from an older draft of the standard)
>
>DKIMPROXY uses DKIM version  draft-01
>
>Can anybody help me?
>
>Thanks and sorry for my bad english.


Questions about dkimproxy should be sent to me directly (jason@...
or jlong@...).

In this case, you are using dkimproxy with the nowsp canonicalization,
which apparently is not supported by the testing service you're using.
You should change your dkimproxy startup file to specify the
--method=relaxed argument.

E.g.
dkimproxy.out --method=relaxed ....



Jason

#18 From: "Carlos Garcia Test" <carlos@...>
Date: Wed Feb 7, 2007 8:09 am
Subject: DKIM signature with QMAIL MTA
soyelcarlos2002
Offline Offline
Send Email Send Email
 
Hello,
 
I am trying to integrate DKIM signature with QMAIL MTA. I canīt belive that DKIM is integrated with sendmail, postfix and other and not with QMAIL.
 
I use dkimproy (dkimproxyout.pl) and it hardly works... The email is signed but in the test it appears this:
 
DKIM-Status: Canonicalization type nowsp is no longer valid (This signature appears to be from an older draft of the standard)

DKIMPROXY uses DKIM version  draft-01
 
Can anybody help me?
 
Thanks and sorry for my bad english.
 
 
This is the test email:
 
MAIL FROM: carlos@...
PRA: carlos@...
SPF-Record-Classic: v=spf1 ip4:213.201.101.250 -all
SPF-Record-MFROM Scope: v=spf1 ip4:213.201.101.250 -all
SPF-Record-PRA Scope: v=spf1 ip4:213.201.101.250 -all
SPF-Method Result: pass(test.f-integra.org: domain of
test.f-integra.org designates 213.201.101.250 as permitted sender)

SenderID-MFROM-Method Result: pass(test.f-integra.org: domain of
test.f-integra.org designates 213.201.101.250 as permitted sender)

SenderID-PRA-Method Result: pass(test.f-integra.org: domain of
test.f-integra.org designates 213.201.101.250 as permitted sender)

DomainKey-Status: good
DKIM-Status: Canonicalization type nowsp is no longer valid (This signature appears to be from an older draft of the standard)
Return-Path: carlos@...
Received: from 213.201.101.250
     by 69.56.15.194
     for <mvp7hbH@...>; Mon, 5 Feb 2007 09:08:46 -0600
Received: (qmail 2987 invoked from network); 5 Feb 2007 15:08:39 -0000
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=default; d=test.f-integra.org;
  b=fNz5qzO0YwOCrGzvyljrPv3jnmvT8rcdSTfyn38MW6qswmJHgk0pE22rxYad2gWR4uQFLeFcUYA/6mc4nwsm2YVDizCbiZ4TPv1158kCY0AN7XA48qnWVUUQV6XT9fZM  ;

Received: from unknown (HELO Baco) (192.168.0.13)
  by servermail with SMTP; 5 Feb 2007 15:08:39 -0000
DKIM-Signature: a=rsa-sha1; c=nowsp; d=test.f-integra.org; h=message-id:reply-to:from:to:subject:date:organization:mime-version:content-type:x-priority:x-msmail-priority:x-mailer:x-mimeole; q=dns; s=default; bh=n6E6gYUVA+mRTwkK8R5P910jzzg=; b=T7gk9t0tt8gl7VHdt/KHGhR3UenCI6WHJ8Vj44KesdiyhlEyXy6sfhkNKaae6RawyPUcp+zmrHd4ee3ha9rJQhs09r1Q4o5DjjRzdVPEzJrxWfZc6WVfd8uJQ3DG0Sxo


Message-ID: <008001c74937$8817d280$0900a8c0@...>
Reply-To: "Carlos Garcia Test" <carlos@...>
From: "Carlos Garcia Test" <carlos@...>
To: <mvp7hbH@...>
Subject:
Date: Mon, 5 Feb 2007 16:08:45 +0100
Organization: Carlos
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_007D_01C7493F.E9C6DDC0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3028
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028

This is a multi-part message in MIME format.

------=_NextPart_000_007D_01C7493F.E9C6DDC0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable


------=_NextPart_000_007D_01C7493F.E9C6DDC0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2900.3020" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV>&nbsp;</DIV></BODY></HTML>

------=_NextPart_000_007D_01C7493F.E9C6DDC0--

 

#17 From: Arvel <arvel@...>
Date: Sat Jun 10, 2006 5:40 am
Subject: Alt-N DK reflector
arvel@...
Send Email Send Email
 
I'm still traveling atm but when I return I'll be happy to help track this down.
In the meanwhile i'm cc'ing somebody at our HQ in case they can get to it faster
than me.

Arvel
Alt-N

-----Original Message-----
From: "Dan Mahoney, System Admin" <danm@...>
To: dkim-testers@yahoogroups.com
Sent: 6/9/06 11:16 AM
Subject: Re: [dkim-testers] Test Results for various reflectors

On Fri, 9 Jun 2006, Dan Mahoney, System Admin wrote:

Okay,

It would appear that I'm now speaking DKIM to all the reflectors out there
that I previously listed, which is cool.  Admittedly, a portion of the
issue was that I had formatted my key DNS entry slightly wrong.

One minor issue remains -- if the person who runs the altn responder could
contact me off-list, I'm still seeing a domainkeys fail there.  (I also
suppose the next step now is to shake down my domainkeys setup by finding
more testers/autoresponders related to that.)

#16 From: "Kamran Habib \(khabib\)" <khabib@...>
Date: Fri Jun 9, 2006 6:16 pm
Subject: RE: Differences between DK and DKIM
kmhab
Offline Offline
Send Email Send Email
 
Hi Mark,
 
Please look at the FAQ on http://mipassoc.org/dkim/info/dkim-faq.html .
 
Thanks,
Kamran


From: dkim-testers@yahoogroups.com [mailto:dkim-testers@yahoogroups.com] On Behalf Of Mark Wishneusky
Sent: Friday, June 09, 2006 6:28 AM
To: dkim-testers@yahoogroups.com
Subject: [dkim-testers] Differences between DK and DKIM

Hello,

I'm testing DK for my company's outgoing e-mail and was wondering
about DKIM. I know the two are similar, if not the same, and was
wondering if I should be focusing on DK or DKIM? Should we wait on
DKIM after the IETF WG gets everything done?

Mark


#15 From: "Dan Mahoney, System Admin" <danm@...>
Date: Fri Jun 9, 2006 4:16 pm
Subject: Re: Test Results for various reflectors
gushi_person
Offline Offline
Send Email Send Email
 
On Fri, 9 Jun 2006, Dan Mahoney, System Admin wrote:

Okay,

It would appear that I'm now speaking DKIM to all the reflectors out there
that I previously listed, which is cool.  Admittedly, a portion of the
issue was that I had formatted my key DNS entry slightly wrong.

One minor issue remains -- if the person who runs the altn responder could
contact me off-list, I'm still seeing a domainkeys fail there.  (I also
suppose the next step now is to shake down my domainkeys setup by finding
more testers/autoresponders related to that.)

-Dan

> On Fri, 9 Jun 2006, Jason Long wrote:
>
>> Dan Mahoney, System Admin wrote:
>>> Reposted to the list, I just realized I just responded only to Nate...
>>>
>>> Okay.  My results for every reflector listed on testing.dkim.org (with
>>> every possible signing mode) are here (and they're DISMAL):
>>>
>>> http://www.gushi.org/dkim-results.
>
> the . is not part fo the url.
>
> -Dan
>
>>>
>>>
>> This URL gives me 404 Not Found.
>>
>>
>>> Interesting notes:
>>>
>>>
>>
>> I have a reflector at test@..., if you want to add
>> that to your list. It implements ietf-base-01.
>>
>>> * Is there code out there to allow one to run their own testing reflector?
If
>>> so, I'd like to run one myself.
>>>
>>>
>> The source code for my reflector is included in the dkimproxy package,
>> found at http://jason.long.name/dkimproxy. If you're interested in using
>> it, let me know; I'll write up a short Howto for using it.
>>
>>
>>
>> Jason
>>
>>
>
> --
>
> "It's buttery kettle ASS corn!"
>
> -Dan Mahoney, Ezzi Computers,
> 10/22/03, 2AM
>
> --------Dan Mahoney--------
> Techie,  Sysadmin,  WebGeek
> Gushi on efnet/undernet IRC
> ICQ: 13735144   AIM: LarpGM
> Site:  http://www.gushi.org
> ---------------------------
>
>

--

Hate fedora with a white hot burning passion right now though ... damn thing is
Linux-XP(tm)

-Bill Nolan
2/24/04

--------Dan Mahoney--------
Techie,  Sysadmin,  WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144   AIM: LarpGM
Site:  http://www.gushi.org
---------------------------

#14 From: "Dan Mahoney, System Admin" <danm@...>
Date: Fri Jun 9, 2006 4:08 pm
Subject: Re: Test Results for various reflectors
gushi_person
Offline Offline
Send Email Send Email
 
On Fri, 9 Jun 2006, Jason Long wrote:

> Dan Mahoney, System Admin wrote:
>> Reposted to the list, I just realized I just responded only to Nate...
>>
>> Okay.  My results for every reflector listed on testing.dkim.org (with
>> every possible signing mode) are here (and they're DISMAL):
>>
>> http://www.gushi.org/dkim-results.

the . is not part fo the url.

-Dan

>>
>>
> This URL gives me 404 Not Found.
>
>
>> Interesting notes:
>>
>>
>
> I have a reflector at test@..., if you want to add
> that to your list. It implements ietf-base-01.
>
>> * Is there code out there to allow one to run their own testing reflector? If
>> so, I'd like to run one myself.
>>
>>
> The source code for my reflector is included in the dkimproxy package,
> found at http://jason.long.name/dkimproxy. If you're interested in using
> it, let me know; I'll write up a short Howto for using it.
>
>
>
> Jason
>
>

--

"It's buttery kettle ASS corn!"

-Dan Mahoney, Ezzi Computers,
10/22/03, 2AM

--------Dan Mahoney--------
Techie,  Sysadmin,  WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144   AIM: LarpGM
Site:  http://www.gushi.org
---------------------------

#13 From: "Mark Wishneusky" <mwishneusky@...>
Date: Fri Jun 9, 2006 1:28 pm
Subject: Differences between DK and DKIM
eversave_dk
Offline Offline
Send Email Send Email
 
Hello,

I'm testing DK for my company's outgoing e-mail and was wondering
about DKIM.  I know the two are similar, if not the same, and was
wondering if I should be focusing on DK or DKIM?  Should we wait on
DKIM after the IETF WG gets everything done?

Mark

#12 From: Jason Long <jason@...>
Date: Fri Jun 9, 2006 1:07 pm
Subject: Re: Test Results for various reflectors
jason_long_name
Offline Offline
Send Email Send Email
 
Dan Mahoney, System Admin wrote:
> Reposted to the list, I just realized I just responded only to Nate...
>
> Okay.  My results for every reflector listed on testing.dkim.org (with
> every possible signing mode) are here (and they're DISMAL):
>
> http://www.gushi.org/dkim-results.
>
>
This URL gives me 404 Not Found.


> Interesting notes:
>
>

I have a reflector at test@..., if you want to add
that to your list. It implements ietf-base-01.

> * Is there code out there to allow one to run their own testing reflector? If
> so, I'd like to run one myself.
>
>
The source code for my reflector is included in the dkimproxy package,
found at http://jason.long.name/dkimproxy. If you're interested in using
it, let me know; I'll write up a short Howto for using it.



Jason

#11 From: "Dan Mahoney, System Admin" <danm@...>
Date: Thu Jun 8, 2006 9:34 pm
Subject: Test Results for various reflectors
gushi_person
Offline Offline
Send Email Send Email
 
Reposted to the list, I just realized I just responded only to Nate...

Okay.  My results for every reflector listed on testing.dkim.org (with
every possible signing mode) are here (and they're DISMAL):

http://www.gushi.org/dkim-results.

Interesting notes:

blackops.org -- doesn't even seem to verify DKIM or DK, just SPF/Sender-ID.
Pointless.

dk.elandsys.com -- in most results simply tells me what my policies in
published DNS are, but says the DKIM test is "not available".
Mostly Pointless.

dkim.org -- seems to only work with allman-base-00, everything else returns a
base64 error.  Also seems to be running a fairly old sendmail which wouldn't
have the right libmilter to support newer versions of dkim-filter.

sendmail.net -- isn't even answering me when I send with ietf-base-00, and on
the others, not one has triggered a domainkeys response.

altn.com -- sees my DKIM passing, but my domainkeys FAILING where everything
else passes.  If this is one of the "testing" sites this makes me feel FAR less
good about even implementing DOMAINKEYS, since four other sites can verify me
and be fine and one of the TESTING SITES is broken. THIS IS BAD. In a
real-world situation this would REJECT MAIL.  Their MTA (MDaemon) seems to be
at issue here.

Considerations:

* I signed using my address danm@... -- if anyone thinks it would
be any different using gushi@... (which also has domainkeys and a policy)
let me know.

* I for a moment considered re-running these tests with dk-milter completely
disabled and only using dkim-milter, but decided against it as this is a
real-world test, and the idea should be to embrace as many possible
non-competing methods as possible, with PREFERNCE for the ability to continue
to use SUPPORTED ones while the DRAFT ones work the kinks out.

* dkim.org mentions a mailing list on yahoogroups that hasn't seen a post since
last november, and which still has not approved me for posting access.

* I am running the latest versions of all milters (dk, dkim, sid) from
sourceforge.  My arguments for dkim-filter are mentioned in the methods.txt
file in each example.

* After my first try I kicked over to putting the domainkeys milter FIRST in
sendmail.cf, because I noted that this is how sendmail.net does it, and I'd
pretty much consider them an example to work from.

* The sendmail milter can sign with three different modes, ietf-base-00,
ietf-base-01, and allman-base-00.  http://testing.dkim.org/reflector.html
mentions:

allman-01
allman-00
draft-allman-01
draft allman-00

(they mention it with and without the word "draft", I am not sure if that's
significant)

In any case, no detail is mentioned about how these differ, unless I feel like
reading the drafts (and no links are provided, even so it would be a TEDIOUS
read).

(the index page stated that that site may be out of date, I'm ccing the
webmaster on this in case he'd like to remove these links).

According to http://testing.dkim.org/reflector.html some of these milters test
on allman-01, which isn't even an option with dkim-milter (interesting because
AFAIK if it's being supported by sendmail.net, it should conceivably be in the
milter that THEY WROTE).

* Per nate's suggestion I've added -H to dk-filter's options -- it doesn't
seem to have helped the incidence of failures.

* Is there code out there to allow one to run their own testing reflector? If
so, I'd like to run one myself.

* Can anyone post contact addresses for issues with these reflectors?
Ideally we need more info, such as: what testing method they're using,
contact address, what standards they support.

Clearly if all these reflectors are failing with the DEFAULT SIGNING MODE
of dkim-milter this represents an issue.

-Dan Mahoney

--------Dan Mahoney--------
Techie,  Sysadmin,  WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144   AIM: LarpGM
Site:  http://www.gushi.org
---------------------------

#10 From: "ajay_varghese" <ajay.varghese@...>
Date: Wed Nov 30, 2005 9:53 pm
Subject: Re: Reflectors capable of handling relaxed algorithm
ajay_varghese
Offline Offline
Send Email Send Email
 
--- In dkim-testers@yahoogroups.com, Jason Long <jason@l...> wrote:
>
> ajay_varghese wrote:
>
> >Hi Everyone,
> >As the current draft of DKIM specify the new algorithm "relaxed" for
> >canonicalization. I am just curious to know the listed DKIM reflector
> >(http://testing.dkim.org/reflector.html) can handle this algorithm or
> >anyone knows a reflector which can handle.
> >Thanks,
> >
> >-Ajay
> >
> >
>
> You're in luck. This was recently discussed on the dkim-dev list. Try
>
> test@d...
>
> and
>
> dkim-test@a...
>
>
> Jason
>

Awesome and thank you, both the reflectors were helpful in handling
the new "relaxed" algorithm. I like the canonicalized version of the
message attached to the auto-reply from dkimtest.jason.long.name, very
much helpful in correcting the algorithm.

-Ajay

#9 From: Jason Long <jason@...>
Date: Wed Nov 30, 2005 4:15 pm
Subject: Re: Reflectors capable of handling relaxed algorithm
jason_long_name
Offline Offline
Send Email Send Email
 
ajay_varghese wrote:

>Hi Everyone,
>As the current draft of DKIM specify the new algorithm "relaxed" for
>canonicalization. I am just curious to know the listed DKIM reflector
>(http://testing.dkim.org/reflector.html) can handle this algorithm or
>anyone knows a reflector which can handle.
>Thanks,
>
>-Ajay
>
>

You're in luck. This was recently discussed on the dkim-dev list. Try

test@...

and

dkim-test@...


Jason

#8 From: "ajay_varghese" <ajay.varghese@...>
Date: Wed Nov 30, 2005 3:49 pm
Subject: Reflectors capable of handling relaxed algorithm
ajay_varghese
Offline Offline
Send Email Send Email
 
Hi Everyone,
As the current draft of DKIM specify the new algorithm "relaxed" for
canonicalization. I am just curious to know the listed DKIM reflector
(http://testing.dkim.org/reflector.html) can handle this algorithm or
anyone knows a reflector which can handle.
Thanks,

-Ajay

#7 From: "Kamran Habib \(khabib\)" <khabib@...>
Date: Thu Oct 13, 2005 9:33 pm
Subject: From dk-milter to dkim-milter (fwd)
kmhab
Offline Offline
Send Email Send Email
 
-----Original Message-----
From:  On Behalf Of Murray S. Kucherawy
Sent: Friday, July 15, 2005 10:52 AM
To:
Subject: From dk-milter to dkim-milter (fwd)

Public recognition of the easy transition from DK to DKIM.
Kudos, gentlemen.

---------- Forwarded message ----------
Date: Fri, 15 Jul 2005 07:44:19 -0700
From: SM <sm@...>
Reply-To: dkim-milter-discuss@...
To: dkim-milter-discuss@...
Cc: dk-milter-discuss@...
Subject: [dkim-milter-discuss] From dk-milter to dkim-milter

Hello,

For those of you doing the transition from dk-milter to dkim-milter, the
transition is straight-forward.  dkim-milter will work with the public
and private keys generated for DomainKeys.  Compile the dkim-milter and
run it with the same parameters as dk-milter.

There is a How-to at
http://www.elandsys.com/resources/sendmail/dkim.html  You can test DKIM
by sending an email to autorespond+dkim@....

Regards,
-sm

[...]
_______________________________________________
estg-general mailing list
http://mipassoc.org/mailman/listinfo/estg-general

#6 From: "Joe Peterson" <joe@...>
Date: Tue Oct 11, 2005 3:05 pm
Subject: Behavior with missing signatures, lack of _policy, etc.
lavaflyer
Offline Offline
Send Email Send Email
 
Hi all, and thanks to those who set up this discussion list!  I'm relatively new
to DKIM, but I think the idea is very promising.

I posted this topic to the dkim-milter list, but I thought posting it here might
be a good thing to do.  I hope it's appropriate for this list...

I've been doing some testing dkim-milter in various scenarios
(including sending directly and sending through mailing lists), and I
wanted to post my results for discussion.  I run Mailman mailing lists
on two different servers, so I am able to test both with and without my
patch that removes previous signatures.  I also patched my copy of
dkim-milter to always include "Authentication-Results:" so I can see the
result, even if the result is "no signature".  I am not sure if these
are implementation issues or specification issues.

---------

Scenario #1: No _policy published and no sig

Authentication-Results: shadow.wildlava.net header.unknown=unknown;
dkim=fail (no signature)

In this case, I sent mail to myself from a domain that does not do DKIM
at all.  There is no _policy published, and there is no signature in the
header.  Forcing the results to appear, I get the above, indicating a
failure with no signature, and I assume header is "unknown" because
there is no sig).  This seems wrong to me - if the domain does not
publish a _policy, the verifier should not expect a signature, and
therefore it should not "fail."  It could report that it saw no sig, but
that none was expected either.  I would think retults would be neutral
at worst, but maybe even something different, like "no result" to say
that it simply has no information.

----------

Scenario #2: A _policy published ("o=~all") but no sig

Authentication-Results: shadow.wildlava.net header.unknown=unknown;
dkim=fail (no signature)

This is the same result as #1, so I assume whether the _policy is
published does not make a difference in this implementation.  I do
expect that it would complain about no signature, but getting a "fail"
is strange, since with this policy ("~all"), a bad signature gets a
"neutral" in this implementation.

-----------

Scenario #3: A _policy published ("o=~all") with valid sig

Authentication-Results: shadow.wildlava.net header.From=joe@...;
dkim=pass

This is the expected result.

-----------

Scenario #4: Through Mailman, old sig removed

Authentication-Results: shadow.wildlava.net
header.Sender=test-bounces@...; dkim=pass

This is the expected result, and the header shows the sender instead of
the from, which makes sense, since the "From" signature was removed by
[patched] Mailman.

-----------

Scenario #5: Through Mailman, old sig not removed

Authentication-Results: shadow.wildlava.net header.From=joe@...;
dkim=neutral (verification failed)

This is a strange one, since the verifier went ahead and used the "From"
signature, even though there is now a "Sender" line in the header.  And
no report was made regarding the fact that a signature using the
"Sender" was not found.  The receiver only knows now that the
verification failed.  So I think it's misleading, since this case is
more of a missing signature case (not that it should be treated any more
leniently, but the receiver should probably know that this is a mail
list resend failing the "From" check only, otherwise, if the "From"
domain changes it's policy to "-all", mail could get tossed).  I can
imagine cases in which the domain would want to set to "-all" (if it
signs all outgoing email) without knowing that mailing lists will be
basically useless for any users on the domain (since there is no control
over whether all mail lists one desires to use start using DKIM, etc.).
  If DKIM becomes adopted, I know I'd want my domain to be able to use
"-all" - otherwise the strength of DKIM is diminished.  But if I then
could never use a mailing list, that would be a problem, so no one but
banks or other such entities would ever be able to use the strength of DKIM.

-----------

I cannot easily test the multiple signature case through mail lists
(i.e. if a "Sender:" line appears and gets signed by the mail list
server), since dkim-milter will not add a new sig to an email that
already has one, even if there is now a new "Sender:" line.  And I would
expect to see, perhaps, both results - the one for the "From" case and
the one for the "Sender" case - it could then decide what to do based on
that, since it has the full info.  Of course, the results of a missing
sig for From or Sender should probably include whether or not there was
a _policy and what that policy was.

                     -Joe

#5 From: "Kamran Habib \(khabib\)" <khabib@...>
Date: Wed Oct 5, 2005 6:54 pm
Subject: DKIM Test Website Launch
kmhab
Offline Offline
Send Email Send Email
 
Hello All,
 
Please have a look at the newly launched DKIM Test website:
 
 
I hope this drives up the activity on the list, with comments/suggestions/sharing of resources etc.
 
Thanks for your time,
Regards,
Kamran

#4 From: "Ajay Varghese" <ajay.varghese@...>
Date: Wed Sep 28, 2005 11:16 pm
Subject: RE: Any Reflector
ajay_varghese
Offline Offline
Send Email Send Email
 
Gaurav,
Thanks, I was able to send my message to all the reflectors you specified. Waiting for the response from the .
 
-Ajay
-----Original Message-----
From: dkim-testers@yahoogroups.com [mailto:dkim-testers@yahoogroups.com] On Behalf Of Gaurav Kapoor
Sent: Wednesday, September 28, 2005 11:26 AM
To: dkim-testers@yahoogroups.com
Subject: Re: [dkim-testers] Any Reflector

Hi Ajay,

We have been successfully using Alt-N's reflector:
dkim-test@... <mailto:dkim-test@...>

You may also want to try the following:
dkim-test@... <mailto:dkim-test@...>
autorespond+dkim@...
<mailto:autorespond+dkim@...>
dktest@... <mailto:dktest@...>
sa-test@... <mailto:sa-test@...>

Gaurav

ajay_varghese wrote:

> Hi Everybody:
> Do we have a reflector setup to verify the signature?
>
> Thanks,
> Ajay
>
>
>
> ------------------------------------------------------------------------
> YAHOO! GROUPS LINKS
>
>     *  Visit your group "dkim-testers
>       <http://groups.yahoo.com/group/dkim-testers>" on the web.
>       
>     *  To unsubscribe from this group, send an email to:
>        dkim-testers-unsubscribe@yahoogroups.com
>       <mailto:dkim-testers-unsubscribe@yahoogroups.com?subject=Unsubscribe>
>       
>     *  Your use of Yahoo! Groups is subject to the Yahoo! Terms of
>       Service <http://docs.yahoo.com/info/terms/>.
>
>
> ------------------------------------------------------------------------
>


#3 From: Gaurav Kapoor <gaurav_kapoor@...>
Date: Wed Sep 28, 2005 3:26 pm
Subject: Re: Any Reflector
gaurav_kay
Offline Offline
Send Email Send Email
 
Hi Ajay,

We have been successfully using Alt-N's reflector:
dkim-test@... <mailto:dkim-test@...>

You may also want to try the following:
dkim-test@... <mailto:dkim-test@...>
autorespond+dkim@...
<mailto:autorespond+dkim@...>
dktest@... <mailto:dktest@...>
sa-test@... <mailto:sa-test@...>

Gaurav

ajay_varghese wrote:

> Hi Everybody:
> Do we have a reflector setup to verify the signature?
>
> Thanks,
> Ajay
>
>
>
> ------------------------------------------------------------------------
> YAHOO! GROUPS LINKS
>
>     *  Visit your group "dkim-testers
>       <http://groups.yahoo.com/group/dkim-testers>" on the web.
>
>     *  To unsubscribe from this group, send an email to:
>        dkim-testers-unsubscribe@yahoogroups.com
>       <mailto:dkim-testers-unsubscribe@yahoogroups.com?subject=Unsubscribe>
>
>     *  Your use of Yahoo! Groups is subject to the Yahoo! Terms of
>       Service <http://docs.yahoo.com/info/terms/>.
>
>
> ------------------------------------------------------------------------
>

#2 From: "ajay_varghese" <ajay.varghese@...>
Date: Wed Sep 28, 2005 2:01 pm
Subject: Any Reflector
ajay_varghese
Offline Offline
Send Email Send Email
 
Hi Everybody:
Do we have a reflector setup to verify the signature?

Thanks,
Ajay

#1 From: "Craig Shaver" <crshaver@...>
Date: Wed Sep 21, 2005 9:40 pm
Subject: First Message!
craigs2
Offline Offline
Send Email Send Email
 
Hi Everybody,

Looking forward to sharing dkim implementation testing information
with all of you.

Craig,

Messages 1 - 30 of 69   Newest  |  < Newer  |  Older >  |  Oldest
Advanced
Add to My Yahoo!      XML What's This?

Copyright Đ 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help