Re: [dmarc-ietf] Which DKIM(s) should be reported? (Ticket #38)
Douglas Foster <dougfoster.emailstandards@gmail.com> Mon, 25 January 2021 12:21 UTC
Return-Path: <dougfoster.emailstandards@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
by ietfa.amsl.com (Postfix) with ESMTP id 8DF963A1171
for <dmarc@ietfa.amsl.com>; Mon, 25 Jan 2021 04:21:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.197
X-Spam-Level:
X-Spam-Status: No, score=-0.197 tagged_above=-999 required=5
tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001,
SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001]
autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id leUuBO6EzZyb for <dmarc@ietfa.amsl.com>;
Mon, 25 Jan 2021 04:21:49 -0800 (PST)
Received: from mail-vs1-xe33.google.com (mail-vs1-xe33.google.com
[IPv6:2607:f8b0:4864:20::e33])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by ietfa.amsl.com (Postfix) with ESMTPS id 7FB133A1170
for <dmarc@ietf.org>; Mon, 25 Jan 2021 04:21:49 -0800 (PST)
Received: by mail-vs1-xe33.google.com with SMTP id 186so7015846vsz.13
for <dmarc@ietf.org>; Mon, 25 Jan 2021 04:21:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
h=mime-version:references:in-reply-to:from:date:message-id:subject:to;
bh=fRLJYcu8hPQFVy2OOmDbEXdvf+hn97I+vzCvmXNaMt0=;
b=Z430CwyP+BkLHxaCeESaCGyKq5Hc+P+IeQ6o7P3AK4usPKNLh7BPfxnKK4pLjER+ze
sY1RArk4OiXMDBgBH5zMp7vEsLALms3sYU6WAvMcV8NWRRCOImv+HVT9mvgNyV4NQ9rj
GQkP/XjQ9w6P8DC4y16lOclUGeBKfTMsdTWVCGMDptePg76U1uFjGGdAX0qQON3aL2Wl
hqjq2AaVesHea3V7GGi2LI2YS4BZGD3cszLZH4R+g2xmHy5R9tVtYhGn8c/3p+sX2EfS
3C2C03e4bjTBsJESTI8Kwg2lC/desOCxRehdVAZFLX/zXVuG3iTDWNNUJ0ntMXsifsmM
Juag==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:references:in-reply-to:from:date
:message-id:subject:to;
bh=fRLJYcu8hPQFVy2OOmDbEXdvf+hn97I+vzCvmXNaMt0=;
b=ZEx+IQbv3cgEzLrsdEW3nQRzQvxvAgkKZioJBeNPVfm1CAH+6GiUCUM61ogFZpeCfz
e7XW9sXDTmkXv4C/muX76guSOvtblcOojryt37ltEQI7ie+0DKi/hy3GxXZcyR4rpuGM
k51DAYXMpgew8qJlMvoiLgdmzJtIjuLjGtoHZM/ON9fu03e6vLA1cFapu13fC8SRi6CF
jIavsSGKBG1BysxVUdG7a4W6yJq4I04heqezSyum6bNnVO6oVsgPU4yVMdwiFN9v43Xz
R1TEcsZ4OVJt2+v5lZ2tgMJmAdZueRu8YTX2gxUzISPw6BrTrOGW8lcyhrwy0Ibknapl
JlKA==
X-Gm-Message-State: AOAM532/PBaNrJN7RB/0i/HFGdVivVsp9JrEvJfpU2w7L84eufNeTWTu
fb345MUoJ3EdQEjKQK+MwRKwLsczG0iE8E7uE2wU6E3nMVU=
X-Google-Smtp-Source: ABdhPJzKRlIqsGjXNmD+Qivc8+tHX2dzU7FC6s2Wm+VQFhhJz/A131gY4JhzfaBlwFL+kNCo1fRHKbgIlofExGwcQ98=
X-Received: by 2002:a67:87c2:: with SMTP id j185mr160495vsd.25.1611577308089;
Mon, 25 Jan 2021 04:21:48 -0800 (PST)
MIME-Version: 1.0
References: <MN2PR11MB4351BD7203D41DB25771D3B3F7BD9@MN2PR11MB4351.namprd11.prod.outlook.com>
<A551B531-BFCA-466A-8E8D-4EA4EF9FC82C@aegee.org>
In-Reply-To: <A551B531-BFCA-466A-8E8D-4EA4EF9FC82C@aegee.org>
From: Douglas Foster <dougfoster.emailstandards@gmail.com>
Date: Mon, 25 Jan 2021 07:21:37 -0500
Message-ID: <CAH48ZfwONFvCunEmD2=PFjbKfb55A=mSB-kjEK-mipWQXx_ahg@mail.gmail.com>
To: IETF DMARC WG <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fa10f105b9b8948a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/qkif2M5vguYVBCrDosu_Wr0R3OY>
Subject: Re: [dmarc-ietf] Which DKIM(s) should be reported? (Ticket #38)
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting,
and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>,
<mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>,
<mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 25 Jan 2021 12:21:52 -0000
This is an interesting issue. Perhaps we need another ticket just to discuss how to handle signature transition. My first thought is that it will be more effective to announce support for ed25519 in the report header, rather than in each message result. Another possibility is for a recipient to indicate support for new signatures in the DMARC policy record. Any report recipient will have difficulty knowing how to extrapolate from a single result or even a single report to a general rule. John has observed that the RUA report does not even indicate the target domain(s) being reported. I would think this data inadequacy should be a priority for correction. For any multi-server configuration, knowing that one IP supports the new signatures does not mean that all servers do so. The challenge becomes knowing whether the domain is fully transitioned, and we don't even know the domain being evaluated. I suspect that a day will come when a research presents evidence that the old signatures can no longer be trusted. At that point, PCI DSS or GDPR will require us to quickly deprecate the old signatures, and compliant systems will simply ignore the RSA signatures. At that point, transition planning is simplified. Dual signatures also create some challenges for ARC. I don't think an ARC Set can reasonably include signatures under both algorithms. Doug Foster On Mon, Jan 25, 2021 at 12:10 AM Дилян Палаузов <dilyan.palauzov@aegee.org> wrote: > Hello, > > lets say a site signs an email with both rsa and ed25519 algorithms. This > site wants to know, whether the recipient can validate the ed25519 > signatures, so that in the future rsa signing for that receiving site can > be skipped (or errors in the ed25519 implementation fixed). > > For this to work the receiving site must put in the report information > about each aligned dkim signature, saying which public key-name was used. > > Greetings > Дилян > > On January 25, 2021 2:25:13 AM GMT+02:00, "Brotman, Alex" <Alex_Brotman= > 40comcast.com@dmarc.ietf.org> wrote: >> >> Hello folks, >> >> Some time ago, an issue[1] was brought to the list where which DKIM(s) being reported is not clear in RFC7489 [2]. There was a short discussion, though no clear resolution before conversation trailed off. It seems like there were points that may need to be discussed. One was whether the reporting SHOULD report all signatures, regardless of alignment or validity, or perhaps just the one that aligns (if there is one). There was also another question if there should be a limit to the number of signatures reported so that it remains sane. >> >> We'd like to try to get this resolved within about two weeks. Thank you for your feedback. >> >> 1: https://mailarchive.ietf.org/arch/msg/dmarc/9-V596yl2BBaUzCNaDZB1Tg1s4c/ >> 2: https://tools.ietf.org/html/rfc7489#section-7.2 >> >> -- >> Alex Brotman >> Sr. Engineer, Anti-Abuse & Messaging Policy >> Comcast >> ------------------------------ >> dmarc mailing list >> dmarc@ietf.org >> https://www.ietf.org/mailman/listinfo/dmarc >> >> _______________________________________________ > dmarc mailing list > dmarc@ietf.org > https://www.ietf.org/mailman/listinfo/dmarc >
- [dmarc-ietf] Which DKIM(s) should be reported? (T… Brotman, Alex
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Дилян Палаузов
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Murray S. Kucherawy
- Re: [dmarc-ietf] Which DKIM(s) should be reported… John Levine
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Brotman, Alex
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Brotman, Alex
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Douglas Foster
- Re: [dmarc-ietf] Which DKIM(s) should be reported… Alessandro Vesely