OT: DKIM signatures on email messages from lists.gnupg.org

Werner Koch wk at gnupg.org
Tue Jun 13 11:40:39 CEST 2023


On Tue, 13 Jun 2023 08:46, Alexander Leidinger said:

> DKIM doesn't specify an automatic removal of a sinature. So I
> postulate there is no DKIM related tool which does this (only

formail -I DKIM-Signature

BTW, the whole DKIM thing does not protect the body of a mail because
for example the Content-type is not commonly included in the hash and
thus you can change the boundary in this header and then tweak the body.
TLR had a PoC within hours after the DKIM idea was original proposed.
It was a major failure not to use established MIME formats for that
thing (protecting headers would have been simple with MIME).


SCNR,

   Werner


-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20230613/fa7daa75/attachment.sig>


More information about the Gnupg-users mailing list