Re: Signing problem

From: Andreas Schulze <sca_at_andreasschulze.de>
Date: Tue, 26 Oct 2010 22:28:02 +0200

Hi Jason,
> mail ~ # host -t txt mail._domainkey.marlborosurvey.net
> mail._domainkey.marlborosurvey.net descriptive text "v=DKIM1\; k=rsa\; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGAq3ldG6D1fJiWoXPDpKg9dx42LhQysLAgMwo7cDrBiPMJ9jKh/YIAPAdFm6lHMWOQiL+IryQH+XCMSecdEj67Uw+EIxMgVT/KNQAH9Lqax8YnM5f91XZrazHLfa8U+bzHrSw15VhXCe9wb+sDtSa3E39naEY7nW5EJRCnCEm0QIDAQAB"
the dnsrecord have 10 seconds TTL. This may be to short. I personaly never use a TTL less then 60 seconds.

> mail ~ # ls -al /var/db/dkim/
> total 24
> drwxr-xr-x 2 root root 4096 Oct 25 15:56 .
> drwxr-xr-x 4 root root 4096 Oct 25 15:56 ..
> -rw------- 1 root root 887 Oct 25 15:55 mail.key.pem
The key is not readable for user dkim.

> mail ~ # cat /etc/mail/dkim/trusted-hosts
> mail.marlborosurvey.net
> 127.0.0.1/8
try adding "localhost.localdomain"

Andreas

-- 
########################################################################
#
# Andreas Schulze
# https://andreasschulze.de
# 
# GnuPG Key-ID: A7DBA67F, https://andreasschulze.de/sca.asc
# GnuPG Fingerprint: 14C1 39A8 CE6D 6BE0 28C6 5652 03B5 6793 A7DB A67F
#
# $Id: .signature,v 1.3 2007-12-27 21:13:36 sca Exp $
########################################################################
Received on Tue Oct 26 2010 - 20:27:31 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:19:49 PST