From owner-freebsd-questions@FreeBSD.ORG Sun Aug 3 08:11:37 2014 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 4F02E599 for ; Sun, 3 Aug 2014 08:11:37 +0000 (UTC) Received: from smtp.infracaninophile.co.uk (smtp6.infracaninophile.co.uk [IPv6:2001:8b0:151:1:3cd3:cd67:fafa:3d78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "smtp.infracaninophile.co.uk", Issuer "ca.infracaninophile.co.uk" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id D18312B26 for ; Sun, 3 Aug 2014 08:11:36 +0000 (UTC) Received: from seedling.black-earth.co.uk (seedling.black-earth.co.uk [81.2.117.99]) (authenticated bits=0) by smtp.infracaninophile.co.uk (8.14.9/8.14.9) with ESMTP id s738BS6G023669 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO) for ; Sun, 3 Aug 2014 09:11:28 +0100 (BST) (envelope-from m.seaman@infracaninophile.co.uk) Authentication-Results: lucid-nonsense.infracaninophile.co.uk; dmarc=none header.from=infracaninophile.co.uk DKIM-Filter: OpenDKIM Filter v2.9.2 smtp.infracaninophile.co.uk s738BS6G023669 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=infracaninophile.co.uk; s=201001-infracaninophile; t=1407053488; bh=56AZJBQQGdDZ+q8rwIksiXDu7dK4GQbO+4XqrN1xcvU=; h=Date:From:To:Subject:References:In-Reply-To; z=Date:=20Sun,=2003=20Aug=202014=2009:11:15=20+0100|From:=20Matthew =20Seaman=20|To:=20freebsd-questi ons@freebsd.org|Subject:=20Re:=20FreeBSD=20lists=20and=20DKIM|Refe rences:=20<1407011530.3895.84.camel@btw.pki2.com>|In-Reply-To:=20< 1407011530.3895.84.camel@btw.pki2.com>; b=eX0q7uSax+Tr2HX8IAE5LzsllLv3/bQqUiuRB6rEy0BC2fK7tZHTcJyJs01/YX0/M SI1e/81lbrAGBdjR9XqECk4Tjcwt1cbiEqcZDAtPW0+PrklflWR8L94GKb8zVK4an6 F6gLsdChQPJcwe6wsEhIHArZRjgLY09KeIsr0sjw= Message-ID: <53DDEEA3.4060702@infracaninophile.co.uk> Date: Sun, 03 Aug 2014 09:11:15 +0100 From: Matthew Seaman User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:24.0) Gecko/20100101 Thunderbird/24.6.0 MIME-Version: 1.0 To: freebsd-questions@freebsd.org Subject: Re: FreeBSD lists and DKIM References: <1407011530.3895.84.camel@btw.pki2.com> In-Reply-To: <1407011530.3895.84.camel@btw.pki2.com> X-Enigmail-Version: 1.6 OpenPGP: id=E1ECF9BB Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="kxCJIOFKXBrOGATVCEO2EtqCSCp8IqCN8" X-Virus-Scanned: clamav-milter 0.98.4 at lucid-nonsense.infracaninophile.co.uk X-Virus-Status: Clean X-Spam-Status: No, score=-2.5 required=5.0 tests=ALL_TRUSTED,AWL,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on lucid-nonsense.infracaninophile.co.uk X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2014 08:11:37 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --kxCJIOFKXBrOGATVCEO2EtqCSCp8IqCN8 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On 02/08/2014 21:32, Dennis Glatting wrote: > Mail coming through the FreeBSD lists often breaks messages signed > through DKIM. What is the policy to resolve this issue? >=20 > Turning off DKIM isn't an option. If there is a signature, such as > someone in the chain coming through gmail, it must validate or the > message is rejected. I understand this is a common problem for email > lists and there are patches available to reformat messages. >=20 > http://tools.ietf.org/html/rfc6377 >=20 > The best general recommendation for dealing with MLMs is that the ML= M > or an MTA in the MLM's domain apply its own DKIM signature to each > message it forwards and that assessors on the receiving end consider= > the MLM's domain signature in making their assessments. (See > Section 5, especially Section 5.2.) If you're in charge of the systems *sending* the DKIM signed messages, then choose the set of mail headers the signature is based on carefully: avoid any headers that would tend to be re-written during processing by the mailing list software. On the receiving side: allow for mailing lists to add trailers to messages that pass. Don't base your acept/reject decisions entirely on whether the message passes or fails DKIM or other tests. The way Spamassassin handles such things is the way to go: DKIM, SPF, automatic white-listing all make a weighted contribution to calculating the score. The advice for the MLM to apply it's own signature to a message is problematic in that it magnifies the cpu load required to process messages quite a lot. At least with DKIM it is possible to do that: compare to what would be needed with SPF, where the MLM would be forced to resend the message as *originating* from the mailing list itself. Matthew --=20 Dr Matthew J Seaman MA, D.Phil. PGP: http://www.infracaninophile.co.uk/pgpkey JID: matthew@infracaninophile.co.uk --kxCJIOFKXBrOGATVCEO2EtqCSCp8IqCN8 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.20 (Darwin) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iQJ8BAEBCgBmBQJT3e6vXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2NTNBNjhCOTEzQTRFNkNGM0UxRTEzMjZC QjIzQUY1MThFMUE0MDEzAAoJELsjr1GOGkAT6TsP/234ZQpzR+oC4J9X4yJYzTWw lLO4ULAUFAMawMR/e6u4PtujU3v/0haZm/GNqxOWtyt1jelQdqioVI/AFjYrF2n0 kj9u7h5FqGIFWuaRdGmhRRblk/9go4UTEG/CKjiDbIKnqSSoDx6uIYseWUxAGQ4C /ikxjwGphE/KjuTLq8atLz8NICFl+XFNJYwBgCvMGVsV7Vf6Y0niF1TO76a4apo5 Kw4aSAMMPDKzyvRvKwcREY8eg/IpD0xkItKSms6jENHmpdZqe19xSu8HQ+WE0OHd 2t0KVcClNOm3TS3XbAD960kOwrMxqPy0xVCtMoqLDkZmvAEgDPDzVVWH9Qqnc7jK FpfdaLwtnEOZ6PTGF/TZPgxtIKJtnw7MHwHPlIELJcozY3j7L/r5xILBB/cJiY+S mN/JQ3G7IeP+EKn3+LntUBfMpAHHrtEw5yMCTa2JzXcIX3//EO1TTSdRaMZOUFDP 743DiFqMy6TnDEM3YbLrVPalTT9nmHpJt7/qz3YGX/esmkw49VngvzuPuEHaniND m9hTDlIqGl1cKzDWjK0cmjmQHONs8ni6Ml6J5+AYLEtNsAo0oAIsXTdjd8yBg8Be HfhZV6M/ZqG8kpYhbmw248ruYFa75rsDgK7uXtkin4WQV3vsS8YAkvJnJFdQKZI3 vg+rjrXbFdd9MeYeSC/e =9Ks/ -----END PGP SIGNATURE----- --kxCJIOFKXBrOGATVCEO2EtqCSCp8IqCN8--