Re: Successful LDAP signing test

From: Mike Markley <mike_at_markley.org>
Date: Sat, 20 Feb 2010 23:00:54 -0800

On Sat, Feb 20, 2010 at 10:52:25PM -0800, Murray S. Kucherawy <msk_at_blackops.org> wrote:
> On Sat, 20 Feb 2010, Mike Markley wrote:
> >I should be able to bang on it today. Thanks for taking the feedback ;).
>
> OK. I'll wait to post Beta4 until I get your go-ahead. Tomorrow I'll be
> launching my multi-OS build farm to make sure various combinations of
> ./configure options are working.

Just ran it. Using the full PEM key in LDAP or the base64 portion with
no header/footer/linebreaks works. Using raw DER as a binary value does
not, but it sounds like that's expected. If you're still using strings
for the key then you'd probably have to switch to DER natively and deal
with the encodings before then, which is a bigger change.

I think this is probably just fine for most administrators. Folks
implementing DKIM are relatively familiar with getting the
base64-encoded DER key from the PEM file; it's required for the
selector, as you pointed out earlier.

So: works for me.

-- 
Mike Markley <mike_at_markley.org>
The heart is not a logical organ.
- Dr. Janet Wallace, "The Deadly Years", stardate 3479.4
Received on Sun Feb 21 2010 - 07:01:05 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:32:52 PST