smtp-sts icon indicating copy to clipboard operation
smtp-sts copied to clipboard

DKIM signature may not cover the entire body

Open aykevl opened this issue 7 years ago • 3 comments

The DKIM signature may not cover the entire body (or any part of the body) using the l= parameter. Thus an email message with a valid DKIM signature could still be tampered with. I think the DKIM signature should cover the entire body, e.g. by disallowing the l= parameter or by requiring it to cover the entire attachment.

See RFC6376 section 8.2.

aykevl avatar Sep 15 '17 20:09 aykevl

Sure, we can add that.

abrotman avatar Sep 18 '17 11:09 abrotman

Looks like it's fixed. Thanks!

aykevl avatar Sep 26 '17 15:09 aykevl

Per https://etherpad.tools.ietf.org/p/notes-ietf-100-uta, Jim Fenton points out that constraining the use of l= seems like a bit of a layering violation. I'm somewhat inclined to agree. l= may be a bad idea, but it's not especially worse here, is it?

danmarg avatar Nov 15 '17 05:11 danmarg