From: Jeremy Harris Date: Thu, 17 May 2018 10:18:04 +0000 (+0100) Subject: Docs: add note on DKIM signing-limit security X-Git-Tag: exim-4.92-RC1~179 X-Git-Url: https://vcs.fsf.org/?a=commitdiff_plain;h=caf6aa3b459c73c266d5c7caf66620afb733fbbb;p=exim.git Docs: add note on DKIM signing-limit security --- diff --git a/doc/doc-docbook/spec.xfpt b/doc/doc-docbook/spec.xfpt index 44022291c..c4b3837da 100644 --- a/doc/doc-docbook/spec.xfpt +++ b/doc/doc-docbook/spec.xfpt @@ -39261,6 +39261,12 @@ strict enforcement should code the check explicitly. The number of signed body bytes. If zero ("0"), the body is unsigned. If no limit was set by the signer, "9999999999999" is returned. This makes sure that this variable always expands to an integer value. +.new +&*Note:*& The presence of the signature tag specifying a signing body length +is one possible route to spoofing of valid DKIM signatures. +A paranoid implementation might wish to regard signature where this variable +shows less than the "no limit" return as being invalid. +.wen .vitem &%$dkim_created%& UNIX timestamp reflecting the date and time when the signature was created.