Re: [openpgp] Put Signature in an Email's Header

Wiktor Kwapisiewicz <wiktor@metacode.biz> Tue, 08 August 2023 12:34 UTC

Return-Path: <wiktor@metacode.biz>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5CACAC1516F8 for <openpgp@ietfa.amsl.com>; Tue, 8 Aug 2023 05:34:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=metacode.biz
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yW64_e5e_sP9 for <openpgp@ietfa.amsl.com>; Tue, 8 Aug 2023 05:34:42 -0700 (PDT)
Received: from out-126.mta1.migadu.com (out-126.mta1.migadu.com [95.215.58.126]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E3FCBC151099 for <openpgp@ietf.org>; Tue, 8 Aug 2023 05:34:41 -0700 (PDT)
Date: Tue, 08 Aug 2023 14:34:36 +0200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=metacode.biz; s=key1; t=1691498079; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=ctJRgqeC3UWe4+tQUs3bVt0cRTtZ2+vu8sIltTfrajE=; b=hlVymeOBJHNgKYD2ED3OluGbaqfcQpMZUCkxcIRdBMKFibalvCNkexMmrAQ/XNc09+F8HH Lsj/7z+aMDcAPVdxKRaGelIpMfIA8TCd8PWbpNRBolglHW+N+FYij26hSfPTPBlUV+VN4Y Z8LwQF+xai1FDZF5mBM2euhaRle/hFo=
X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers.
From: Wiktor Kwapisiewicz <wiktor@metacode.biz>
To: Andrew Gallagher <andrewg=40andrewg.com@dmarc.ietf.org>
CC: Werner Koch <wk@gnupg.org>, IETF OpenPGP WG <openpgp@ietf.org>, Kai Engert <kaie@kuix.de>
In-Reply-To: <E6B2A53A-D5AE-4267-9224-FC01DFA3C404@andrewg.com>
References: <48be3fcf-cdce-9ef4-655b-63b6dddf9310@kuix.de> <20201211095836.5218a72e@computer> <cd02d2db-0671-dfc0-dab3-dc793a2c1605@metacode.biz> <878sa4y7hy.wl-neal@walfield.org> <4dbaf770-2b2e-47cc-afb5-3ba07706aafd@kuix.de> <87a5v1j4xo.fsf@wheatstone.g10code.de> <db447915-fc25-4759-879e-b64020c0ec0e@kuix.de> <87zg31hoee.fsf@wheatstone.g10code.de> <ba560bb0-0fa5-40a2-b70d-83f36859e17e@metacode.biz> <87v8dphmec.fsf@wheatstone.g10code.de> <8d42f591-3aec-43c8-b476-abdafdb85dd7@metacode.biz> <E6B2A53A-D5AE-4267-9224-FC01DFA3C404@andrewg.com>
Message-ID: <373C83F2-A8FF-43B8-B47A-3CE332D62E68@metacode.biz>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Autocrypt: addr=wiktor@metacode.biz; prefer-encrypt=mutual; keydata= mQINBFhoYHoBEADzmg9UuwDrtvyejU01gDY1J1iJiCi4XGJ4lCfYeLC2jSagIxU/5Lu0lRft0Loi 2tsjpo0c8docP7HFxafEEvnnt/iabd6I536llMuw0uno4PgnD3ljcCMZLT+vn+amIDtalzVoMnSq zoNUotMNMtjIFuAaQ/wr4/Mp9CIgJdviGUc3PscqUiiUVVtk6uF0x657NULZgSIT/Mrqlr2i4Ruy PwXe2Qt0uEA3KWWjF0l2NpAMVrqz+nHsLoNOaAsfdx94bzKQrrSeSQqEO2f+/eO/hbUAFAmEhrot mUO8wJNygo8TgkdlzFI+UE4p8/KW0aCgGGgR8YkCvHq2OQhAAYFNJoNzHqw0FGxdsY8qWFkYpoSB 8zKspNy8KliofCamMYXoPF7eVIxIiKvxrAykGP4jNnzSoV0cn+bYfXnox1IhnqbnoJIT7kTmXv4J mWoYm8ThHqpEgcQOUUQzSRXb9OiNwiXT71ijeO1qswMRpsgk6AGKSZGWxa3c4ive/p8z1Ax27BFZ Sh2FceIcMCcGLrDjnQYgeFsAJ1jSxZQXkGuJFHfb4nffBig7aq/vyKrQFQXG0NQQL7rZAdk/s665 vifos0yPmRDu7yDT1ggdyBp4Pa4re+ZJcNRNzNHozU9al+CoImCQjnTtKMXmOe/BzGrpHI4QR3NN zVa423WCIWkHfwARAQABtClXaWt0b3IgS3dhcGlzaWV3aWN6IDx3aWt0b3JAbWV0YWNvZGUuYml6 PokELgQTAQoCGAIbAQgLCQgHDQwLCgUVCgkICwIeAQIXgDQUgAAAAAASABlwcm9vZkBtZXRhY29k ZS5iaXpkbnM6bWV0YWNvZGUuYml6P3R5cGU9VFhUXBSAAAAAABIAQXByb29mQG1ldGFjb2RlLmJp emh0dHBzOi8vZ2lzdC5naXRodWIuY29tL3dpa3Rvci1rLzM4OWQ1ODlkZDE5MjUwZTFmOWE0MmJj M2Q1ZDQwYzE2VRSAAAAAABIAOnByb29mQG1ldGFjb2RlLmJpemh0dHBzOi8vd3d3LnJlZGRpdC5j b20vdXNlci93aWt0b3Itay9jb21tZW50cy9ibzVvaWgvdGVzdC9zFIAAAAAAKgBAdGltZXN0YW1w K2JpdGNvaW4tdHJhbnNhY3Rpb25AbWV0YWNvZGUuYml6YWZjYjA5MmM1Y2E2NDA5NTI2ZDE4YWU5 Y2YyMmQzYjU1ZDM3ZTcyM2ViMWI3NGUzZjg0ZjdlNmIwNTJhMTYyYUgUgAAAAAASAC1wcm9vZkBt ZXRhY29kZS5iaXpodHRwczovL25ld3MueWNvbWJpbmF0b3IuY29tL3VzZXI/aWQ9d2lrdG9yLWs3 FIAAAAAAEgAccHJvb2ZAbWV0YWNvZGUuYml6aHR0cHM6Ly9tZXRhY29kZS5iaXovQHdpa3RvchYh BGU5CaLw43wQb1+vVGyIV+DY6PB0BQJjjdcHBQkNKkjJAAoJEGyIV+DY6PB0crgQAOjVg6U3Jckf SCCeUQphX5q9QShf29WNNmZI7x3FO5Img2ZMbnrdq9gm3MhvDMTwJF0r7oCy+2BOem8HmLsu+nsO xMSe+dwZwl1pH4lkP4SCMYlemXnqZ/Mdzc2xZuzbjK36HmtqCe7yBzhpriTCvbiqBC6ryGc7BU/P RcfGh+0bG3Ux8sRJaJUrUFLABU+kvClPIj0xlmvpbxY9ND32Hid8Rpiyd7ur80NC8AtKzeJ88Zgu v4CQG1hx8OdlzJVDDvhfhNw6EL7Ja2vhrrbsgIkw5IsWgFAj3Nj/P0FtMK+rG0Q4BCB4mYNrR20o oyvToJNJlx11ytRpFwSE5FkBQATFtnFXYsPMwDodwKR31ipuYlpWC1SscDXs2ngDQ95G2ncogUN5 rKdjTqwVO14SKtK92kGVYVMbyHIEHAg/nf3YlSrI23Pw8JGgUMaHV9Cd1/9T4Sz4wyDxGzH+2cjl BKf17/XZyAIipvhPPPFLRX+3F2Kg0u986Tgm55ylWWvra0vqFjM11aDB3ZM/yYXrrxKI1dL99TBW eb/sbRCV69MvazSRRhO707L9/UmfrROAXJEEPXG1YusW7D6d7e5oGyyZ8tvqDOJWzStJcfgtD9QN d9Q/Ga09qzH7KTZmvnPCivZ7a3RSEsRRNDPylAY/fmMjEYNAqVSN03TBLM3+hirjuDgEX+r8mxIK KwYBBAGXVQEFAQEHQG2SJJLUORlkv9OKpkRYnAGXMCu7qr0CeKiVr6sNJdJHAwEIB4kCPAQYAQoA JgIbDBYhBGU5CaLw43wQb1+vVGyIV+DY6PB0BQJjjdc7BQkFp6ynAAoJEGyIV+DY6PB0YRwQANIp PUclU3oVMd1GQh0CWrxut+TXilVIBdNteqIj+4jQvCr5ERMe3+zUevnn4YjB+0gpjfIxWnfWMqNV +MJMr3kZIwgqz/CjYGtOQfl69+8CBDMbr/WmMYQF9Sfq8uRBQiwpKrwT/ugJMtke1noSPNRgvo3p yEdT2H3WihRSeH410D2bCD34ywejoavS268fZqDHd4atvZsojpTOgysKMTIEWStKHCObctHwQAtd NiGFKf3qo/sPLwWBB6uV0KZ0/TFrMPzt9KziCLtFob1mZIV7HeqJsAWO0jhkv2bW95L6LlyORMVi L0rSjUsC73YEiKaM6+Dx9Wyn46tuibQnGgG6kBVpqci+B9dulhvzuRIAdO/OXSOmFG7zPvLR6ZBq O8zRsc3p3w15YQxx7ItRPqkVlm8P1ddmKZL17jX3eb54aFT4QgURg4Hp6sY3AQxU4x5wypihcetT /i0qI/zpypSxi4ROnidTmkkJzpxtlv6T4HwA2nM63RSwrJWcbdOBAFQG7Q1TNryp9NEGorNljtoN kBrcvPr3jGktSzscvIoAOprurKIn2nE3dLfx/jWrHYbu6lAsOs5OgHRO9McqQ9twDR3GoXTMZjaL vLEM5UcN9V4F3rsehZsram64yNJY/H7QNdtH8dPKHdOGc8C43m/mwe3OFs6vM+raW9aAWHvzuDME X+r8XRYJKwYBBAHaRw8BAQdA9eXMLzdrYx9lRghj8n5DKavvHifb1bCLH0pbR2XViXqJArMEGAEK ACYCGwIWIQRlOQmi8ON8EG9fr1RsiFfg2OjwdAUCY43XOwUJBaes5QCBCRBsiFfg2OjwdHYgBBkW CgAdFiEE5+K4SjZFe+o/Q2kt5ovjsxL6M/wFAl/q/F0ACgkQ5ovjsxL6M/wKCgEA2Dlv8WYhqdGo smTs2A7YF1UUXMEfDsI6x46r1vgmT5QA/jhBg1Es7S1W/IushOfl1rTHwoUqXBOVcIRfl5IXcvEK 1McP/0e8EOjGnU2FvJxhkj5BB7B55oHRKxoVrTAQFbVsuyEF7FbDmXRqUMnPvHF1bHtRqq4JBNpY eesPgaIOjb6zBgiLInIXutc/sjQton1NGqS82H/hetKQaVr1/eCnSXbPWwdSa8y6SXuYM2oDLxwQ 0p3SyCyTVeidJ6EuzWimcw2Dc0snd0s3ZK2CtAC3aJazy64eNBEWqvBoCmPUgNb4cCJpJQuVBiGg rwKoQIZhcSKJ6VNcekZin0i+icuByrVGkeP63BIqzCwytZGAU8Rj7MNPTNz8/PJOXwaTC0LFgUCK nYRHwuHUeWlBdPkIj17dxsA0cef0msFo25YcBmwW1HIZqQK+dZNjSIKBvi4PrsCBdt1qCzO/6ZOT +kJExB0TJLqVfFBWfDxN+31wIEvTXOGALeSsYtw7GkKdnrXyW9mJhPQrIbvCBqaoNy9gqSBVmSu5 A5ePL3DOycs3LRSZHZNSHczpes2MMRpFmh+EfSvAb4S1c3FrJ2FSJVAOHGufmUuPlIjEps8HxjPl 93mEvjPOyliTZk7Gi8uJ8pYEyHxB57OE3jg/hNYBUegPhTcsCziMpL5+YOGghhmVGqsjpY5Lf2W1 KOAlIGSZymD1dSVEIwDDdWBQCIysyC/KP2JEG1shvzyM8Uz7tYwhb0lcX8AXmRrlrFemt3hIllzP V8YE
X-Migadu-Flow: FLOW_OUT
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/T9abtmjHmDrfGJNhH0MNWzjetNc>
Subject: Re: [openpgp] Put Signature in an Email's Header
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Aug 2023 12:34:47 -0000

> We have a specific concern raised, which is that it might break forwarding. So how would this be addressed?

It doesn't break forwarding. It's actually the opposite: forwarding breaks it, or to be more specific rewriting emails breaks the signature.

The same problem appears with DKIM which is widely deployed and I suggest the same solution: don't rewrite user's emails.

Some mailing lists already use this approach (like sr.ht) some (such as this one) don't and as a result end up messing up emails addresses of senders (like yours or mine) and/or stripping DKIM signatures.

Kind regards, 
Wiktor