Re: verification error: empty key record; insecure key

From: Benny Pedersen <me_at_junc.org>
Date: Fri, 17 Aug 2012 18:19:44 +0200

Den 2012-08-17 08:51, Murray S. Kucherawy skrev:

[snip]
> I've posted a question to the unbound-users list to see if there's
> any insight into this issue over there. If it's not a bug in their
> code or documentation, then there might be something we're doing
> wrong
> with how we're calling libunbound that needs fixing.

could this be the problem i see here with RSA-VERIFY failing ?, it
happends most on gmail and ietf, i dont think there dkim is failling,
but is RSA-VERIFY bogus error for not getting correct dns results ?

dig ietf1._domainkey.ietf.org txt

works, so why does opendkim fail with it ?

not using unbound here

is version of libcrypto and libssl to old here ?

Aug 17 00:02:49 home opendkim[3330]: 56E3E25C022: s=ietf1 d=ietf.org
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 05:17:37 home opendkim[3330]: 5A65325C022: s=mail d=mail.ru SSL
error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 05:46:54 home opendkim[3330]: 3D99F25C022: s=ietf1 d=ietf.org
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 07:36:00 home opendkim[3330]: EDB6125C022: s=dkprod001
d=tiggee.com SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad
signature
Aug 17 08:02:15 home opendkim[3330]: DFB3625C022: s=iport d=cisco.com
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 08:29:13 home opendkim[3330]: F3AAC25C022: s=20120113
d=gmail.com SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 08:32:50 home opendkim[3330]: 712ED25C022: s=2007-00
d=kitterman.com SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad
signature
Aug 17 10:02:59 home opendkim[3330]: 6065B25C022: s=smtpapi
d=booking.com SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad
signature
Aug 17 11:15:00 home opendkim[3330]: B60D425C022: s=ietf1 d=ietf.org
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 15:56:34 home opendkim[3330]: D6BBD25C022: s=ietf1 d=ietf.org
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 15:58:42 home opendkim[3330]: 4157325C022: s=ietf1 d=ietf.org
SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature
Aug 17 17:06:39 home opendkim[3330]: 10DD025C022: s=medusa3
d=blackops.org SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad
signature
Aug 17 17:41:58 home opendkim[3330]: 313C325C022: s=20120113
d=gmail.com SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature


[I] dev-libs/openssl
      Available versions:
        (0.9.8) 0.9.8u 0.9.8v 0.9.8w 0.9.8x
        (0) 1.0.0h 1.0.0i 1.0.0j ~1.0.1a ~1.0.1b ~1.0.1c
        {{bindist gmp kerberos rfc3779 sse2 static-libs test vanilla zlib}}
      Installed versions: 1.0.0j(14:41:07 13-05-2012)(zlib -bindist
-gmp -kerberos -rfc3779 -sse2 -static-libs -test)
      Homepage: http://www.openssl.org/
      Description: full-strength general purpose cryptography
library (including SSL v2/v3 and TLS v1)


unsure why it just happen on some domains and not all

what openssl version is stable with opendkim could be usefull if i
should create a bug in gentoo with this problem
Received on Fri Aug 17 2012 - 16:19:41 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:20:42 PST