[ietf-dkim] drop requirement to sign "From" or other "originator" headers?

Eric Allman eric+dkim at sendmail.org
Thu Jul 13 15:14:49 PDT 2006


In listening to the responses and looking over the text, I see 
general agreement, except for Hector --- but only from a very small 
set of people.  Also, saying everything is optional creates an 
interesting glitch in the text: currently at least one header field 
must be included, and changing h= so it can be empty will require 
more thought.

So, for -04 I change my proposal to go back to the wording that says 
that From MUST be signed (since, as Hector points out, From is 
required, we don't have to worry about what to do if it is missing). 
We also said in -03 that "any header field that describes the role of 
the signer" MUST be signed; I'm inclined to leave that out of -04. 
There will informative commentary about what a signer probably wants 
to do.

Folks OK with that?

eric


More information about the ietf-dkim mailing list