[EAI] Re: "7. Upgrading downgraded header"
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[EAI] Re: "7. Upgrading downgraded header"



Charles Lindsey wrote:

>> In other words any valid 2321 or 2047 =?UTF-8...?= encoded word could
>> be encoded in the original message/utf-8 (before downgrading).  Then
>> "upgrading" it would replace the encoded word by native UTF-8.  And
>> that could cause havoc for header signatures.  But we know this, the
>> issue has to be noted somewhere (maybe as "security consideration").
 
> Which implies that any RFC2047 stuff should be unscrambled before
> computing the hash for the signature. That would mean a different
> canonicalization algorithm, but if a special canonicalization algorithm
> is needed for DKIM-signing of UTF8SMTP messages, then that is not a
> showstopper.

It's interesting for my "master plan" to keep all-ASCII in Content-*,
you can't "unscramble" it where that's forbidden in MIME version 1.0.

And _any_ 2047 (or even 2231) stuff isn't possible, implementations
would be forced to know _any_ charset.  And "unscrambling" 2231 would
remove the language tags, unless you intend to use the Unicode tags 
in plane 14 (officially deprecated).

This EAI effort is a can of worms, kill one, find three new.. :-(

Frank



_______________________________________________
IMA mailing list
IMA at ietf.org
https://www1.ietf.org/mailman/listinfo/ima




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.