[Ietf-dkim] Re: Review Response #7: Header Fields

"Murray S. Kucherawy" <superuser@gmail.com> Thu, 17 April 2025 21:53 UTC

Return-Path: <superuser@gmail.com>
X-Original-To: ietf-dkim@mail2.ietf.org
Delivered-To: ietf-dkim@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 060F01DD67BF for <ietf-dkim@mail2.ietf.org>; Thu, 17 Apr 2025 14:53:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.723
X-Spam-Level:
X-Spam-Status: No, score=-1.723 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_XBL=0.375, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yrOH3m1teqc9 for <ietf-dkim@mail2.ietf.org>; Thu, 17 Apr 2025 14:53:48 -0700 (PDT)
Received: from mail-ed1-x52a.google.com (mail-ed1-x52a.google.com [IPv6:2a00:1450:4864:20::52a]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 749101DD67AF for <ietf-dkim@ietf.org>; Thu, 17 Apr 2025 14:53:48 -0700 (PDT)
Received: by mail-ed1-x52a.google.com with SMTP id 4fb4d7f45d1cf-5ed43460d6bso2009493a12.0 for <ietf-dkim@ietf.org>; Thu, 17 Apr 2025 14:53:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1744926827; x=1745531627; darn=ietf.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=+XfhXdI6B3uUK/2EIC3vnwHF0u5MxCKyDlSMGy4pnLs=; b=TlfZaa570U0uFYctJQ+1IKXYildjheIrX40Y13ROQUvtDGZJr08lR8va3h5ik/Cyqv +EdePQ90szBndPOgHBZ8YPf0RyWewms9yd4PAV2FF27uozRVBYHvs/SlcG7kTg0JNenV K2kurSfPfGae4TbviqtVKl+RLWglOC5IkFisYplPXMAX8SbOAProPOjMawSl0gDM9cIu YOT8Dv16+h0UAGWEexzIjBQuEJ1zREVVIpRtEHkN+iwzZ2fXinKP7lM+GZ+b/Y4jMuWI 0M0L8Y0+yVV9UfPAsRuDHpt5prNZlSTxRCvFSWko4K1KMjN7bZNRtfTF6Rl+jFa/28DY K1aA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744926827; x=1745531627; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=+XfhXdI6B3uUK/2EIC3vnwHF0u5MxCKyDlSMGy4pnLs=; b=dMtA344P9o3YclV/5J6hCaNJ8MJ9pvube5hQjhwftM6GGNtAH3IRQPW8vx9IeYW6tp 3CG4lFPnKNcqsU910rCE8tagw7mMsrfMoh3FhePwUXan1nTg4++yWeP+nRA2JODkA3jg 8yYsYiKOPxSxPwaOarOg5oDRVGSjyhNSz/I97btQE7WQ8RVpZdaucfUNXrxzHXgkzEzS eIMHn5MW8tKzKb33a57eeYkJa6ODSZG4wc0G5eoV8kQ6mm8Hkk5/qfISmvhwPxrSJhF+ SlC+AX0Mw9Qhg5wRaDaoqhuKBrD8p/bmlDroX0feDNx0mjRh0nyLnA2G8CXIoJ7wE3Tm lwig==
X-Gm-Message-State: AOJu0YyVFY01ZzhNu3rzR75gvnQ7+8BgYiBJ8K1ByYGWTYnH20/eVzka 5W/1nrt5aZC9hbP1gt5WXasVEYWJVuhYXNcqX48TFxpgY7gtFXiHhusXaorTBZZntE4KyZyDc/K g+FaxRr/Spm7AYs7j45EusvJchAHHzQUm
X-Gm-Gg: ASbGncu1dIQL5+s+TiBLRagLkYxBKi1FpEA3aQQSGxg8dXXHPly7vx6HN4t3pZAMomT IUrCLXQodZcliBRlWT5bVT9xYdgv4Nd3uwoUA4ws2pmO7vFibe/H+Bjxu1pMbkyYnxblSozsff8 cCWrApSI7q5iQT6+9YPiXU3hdNv5CbQlEI
X-Google-Smtp-Source: AGHT+IFFD2piPDnwZqNitX29urOwH47+b5GbxzMysfpjMvyX6UeT/WzWJ4Y3tm7ZISAssPOF3W1jpPgJsdZ7V5XRhJU=
X-Received: by 2002:a17:907:972a:b0:aca:d861:877b with SMTP id a640c23a62f3a-acb74dda76amr26413666b.49.1744926826419; Thu, 17 Apr 2025 14:53:46 -0700 (PDT)
MIME-Version: 1.0
References: <5hVtuaBBTX+nFAzi@highwayman.com> <e5195117-bf74-4c49-8d4d-574ae9a3d29b@dcrocker.net> <0LMO0YNle++nFAAa@highwayman.com> <7740daba-bcdf-47cd-b810-ae0843a2b947@dcrocker.net> <766f0436-ebbb-4d12-b110-33d92d156bc4@app.fastmail.com> <CABZJ8kkdzdhzgvYp7sTcGXF7uNT8O6SPg8qt7wKMyYbOAzAwsQ@mail.gmail.com> <3b3fd81c-e501-475b-9ed6-e700781ed374@dcrocker.net> <CABZJ8kkdnSWGU20WpZrgH2-Yp0V7aoKbjxWOLbSiV0Gmn+hcAg@mail.gmail.com> <5df9212c-5014-4323-8d70-fbc7d044bd97@app.fastmail.com> <CAL0qLwZQxF71ztGBVPBxRWGFOt8SefXusKARY2MjGKJyWEqooA@mail.gmail.com> <20250416172847.8886EC4E0579@ary.qy> <20250416174856.ASXeYj5H@steffen%sdaoden.eu> <20250417183416.pEsXUPod@steffen%sdaoden.eu>
In-Reply-To: <20250417183416.pEsXUPod@steffen%sdaoden.eu>
From: "Murray S. Kucherawy" <superuser@gmail.com>
Date: Thu, 17 Apr 2025 14:53:34 -0700
X-Gm-Features: ATxdqUGppjC3tOg21tlTbSas6uhOWYLOh-u2iB2z85IPcF4px54hnqaQ47YL_n8
Message-ID: <CAL0qLwZ_5HmYeAzn+d-yH-BEbL08oH5=3ixzTpaeiOxZPYP6ag@mail.gmail.com>
To: ietf-dkim@ietf.org
Content-Type: multipart/alternative; boundary="000000000000a5df580633006f48"
Message-ID-Hash: 5NDTYPBBTUK6F4HSJFHYD6JVOVU2AUK2
X-Message-ID-Hash: 5NDTYPBBTUK6F4HSJFHYD6JVOVU2AUK2
X-MailFrom: superuser@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ietf-dkim.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Ietf-dkim] Re: Review Response #7: Header Fields
List-Id: IETF DKIM List <ietf-dkim.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-dkim/G1xEBo7UQ9f9AAwuRnbt7e7Frms>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-dkim>
List-Help: <mailto:ietf-dkim-request@ietf.org?subject=help>
List-Owner: <mailto:ietf-dkim-owner@ietf.org>
List-Post: <mailto:ietf-dkim@ietf.org>
List-Subscribe: <mailto:ietf-dkim-join@ietf.org>
List-Unsubscribe: <mailto:ietf-dkim-leave@ietf.org>

On Thu, Apr 17, 2025 at 2:47 PM Steffen Nurpmeso <steffen@sdaoden.eu> wrote:

> This only survives because DKIM specifies ~"one successful
> verification is enough".  It is a shame given that other
> mailing-lists ensure the original==broken signature is removed or
> renamed, but not even a bug report can change the situation for
> IETF lists!  This makes me sad.
>
> [...]

I give an example, here Jim Fenton's last message.  Sorry for
> that, but i filter out my own (on ingress):
>
>   DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=
> bluepopcorn.net; s=supersize; h=Content-Transfer-Encoding:Content-Type:
> MIME-Version:Message-ID:Date:Subject:To:From:Sender:
> Reply-To:Cc:Content-ID:
> Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
> :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
> List-Subscr ibe:List-Post:List-Owner:List-Archive; bh=..; b=..;
>   From: Jim Fenton <fenton@bluepopcorn.net>
>
> Consciously broken by the IETF.  But many verifiers will try it
> first, and can only fail.  For ACDC i would want to avoid that,
> somehow.  It is -- sorry moderator -- total brain damage, is it??
> (And noting that, in my personal opinion, including List-* for
> sealing in an initial private DKIM signature is .. interesting.)
>

Sorry, what broke here?  The signature itself isn't enough to understand.

If there's something the IETF's list servers are doing wrong, we can ask
the tools team to look into it.

But let's not bog down this WG with that discussion.

And then: how could my domain *know* that it was the IETF list
> that broke the signature?  I know its DKIM signature is correct,
> but i would not know, i could only believe that Jim Fenton's
> initial DKIM signature was correct, too.  Now his signature is
> still in, and broken, while he is still "RFC5322.From".
> (And hey: he *sealed* List-* headers!!!)
>

If Jim's server is signing List-* fields for a message that hasn't gotten
to a list yet, that seems like it guarantees this message will have DKIM
problems.  But again, that's not really on topic for the current
discussions.

-MSK