Re: "unprotected key" with DNSSEC

From: Jim Fenton <fenton_at_bluepopcorn.net>
Date: Tue, 30 Aug 2016 22:01:06 -0700

Yes, apologize for incomplete info. I think one of the subsequent
answers covered it, but for the record:

On 8/30/16 6:15 PM, Benny Pedersen wrote:
> On 2016-08-31 01:39, Jim Fenton wrote:
>
>> Authentication-Results: v2.bluepopcorn.net; dkim=pass
>> reason="1024-bit key; unprotected key"
>> header.d=bluepopcorn.net header.i=_at_bluepopcorn.net
>> header.b=WwWpOCSI; dkim-adsp=pass; dkim-atps=neutral
>>
>> Any ideas?
>
> what version of opendkim ?, what version of openssl ?
opendkim: OpenDKIM Filter v2.9.2
    Compiled with OpenSSL 1.0.1t 3 May 2016
    SMFI_VERSION 0x1000001
    libmilter version 1.0.1
    Supported signing algorithms:
        rsa-sha1
        rsa-sha256
    Supported canonicalization algorithms:
        relaxed
        simple
    Active code options:
        QUERY_CACHE
        USE_DB
        USE_LDAP
        USE_LUA
        USE_ODBX
        USE_UNBOUND
        _FFR_ATPS
        _FFR_RBL
        _FFR_REPLACE_RULES
        _FFR_STATS
        _FFR_VBR
    libopendkim 2.9.2: atps query_cache


>
> how did i spot you have a old version of opendkim ?, adsp is depricated
Yes, quite aware of that :)
>
> dont know if its just missing dnssec then
>
> https://dane.sys4.de/smtp/bluepopcorn.net okay
>
> is ssl enabled or gnutls, is it unbound or bind ?
Received on Wed Aug 31 2016 - 05:01:25 PST

This archive was generated by hypermail 2.3.0 : Wed Aug 31 2016 - 05:09:00 PST