This isn't exactly a bug with opendkim in and of itself, but it is very ironic that the setup of the opendkim user's list breaks DMARC.
Return-Path: opendkim-users-bounce@lists.opendkim.org
Received: from edge01.zimbra.com (LHLO edge01.zimbra.com) (10.210.0.174) by
mbs01.zimbra.com with LMTP; Tue, 5 Jan 2016 16:10:40 -0600 (CST)
Received: from localhost (localhost.localdomain [127.0.0.1])
by edge01.zimbra.com (Postfix) with ESMTP id DA7A344297
for quanah@zimbra.com; Tue, 5 Jan 2016 16:10:39 -0600 (CST)
X-Virus-Scanned: amavisd-new at edge01.zimbra.com
X-Spam-Flag: YES
X-Spam-Score: 9.381
X-Spam-Level: ***
X-Spam-Status: Yes, score=9.381 required=3 tests=[DCC_CHECK=1.1,
DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DMARC_FAIL_REJECT=9,
HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_LOW=-0.7,
RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01]
autolearn=no autolearn_force=no
Authentication-Results: edge01.zimbra.com (amavisd-new);
dkim=pass (1024-bit key) header.d=opendkim.org header.b=kfs398K2;
dkim=fail (1024-bit key) reason="fail (body has been altered)"
header.d=zimbra.com header.b=U3SJAPJ1
Received: from edge01.zimbra.com ([127.0.0.1])
by localhost (edge01.zimbra.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id vaEhdvWd77WT for quanah@zimbra.com;
Tue, 5 Jan 2016 16:10:38 -0600 (CST)
Received: from mx.elandsys.com (ns1.qubic.net [208.69.177.116])
by edge01.zimbra.com (Postfix) with ESMTP id AE61044296
for quanah@zimbra.com; Tue, 5 Jan 2016 16:10:38 -0600 (CST)
Received: from lists.opendkim.org (IDENT:nobody@localhost [127.0.0.1])
by mx.elandsys.com (8.14.5/8.14.5) with ESMTP id u05Ll6NM007175;
Tue, 5 Jan 2016 13:47:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=opendkim.org;
s=mail2010; t=1452030547; x=1452116947;
i=opendkim-users-bounce@lists.opendkim.org;
bh=wB+snPcei+lSACAfm6fL05PIrFWpfZPA4/NlpH3L+7k=;
h=Date:From:To:cc:Subject:In-Reply-To:References:List-Help:
List-Unsubscribe:List-Id:List-Subscribe:List-Owner:List-Post;
b=kfs398K2omS4gboRYDq1VC4VIxCquYU6WjlGtCK7YyMBXwv2EPLVkhMDFDdo/6tpo
dpNwrDMLSpmazvCSFjyUwTKLoWKduNuPjKuKSzt+XUWiDRM/HwCekzDlPqsJITQiDz
EU8N2HM7dR2L6geXh6FD1Nv3SLXQ5sejosuvWjCE=
Received: with LISTRIA (v1.0.0; list opendkim-users); Tue, 05 Jan 2016 13:47:06 -0800 (PST)
Received: from edge02.zimbra.com (edge02.zimbra.com [162.209.122.184])
by mx.elandsys.com (8.14.5/8.14.5) with ESMTP id u05LkvVP008879
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
for opendkim-users@lists.opendkim.org; Tue, 5 Jan 2016 13:47:04 -0800 (PST)
Authentication-Results: mx.elandsys.com; dkim=pass
reason="1024-bit key; unprotected key"
header.d=zimbra.com header.i=@zimbra.com header.b=U3SJAPJ1;
dkim-adsp=pass
Received: from localhost (localhost.localdomain [127.0.0.1])
by edge02.zimbra.com (Postfix) with ESMTP id 15435A6283;
Tue, 5 Jan 2016 15:46:51 -0600 (CST)
Received: from edge02.zimbra.com ([127.0.0.1])
by localhost (edge02.zimbra.com [127.0.0.1]) (amavisd-new, port 10032)
with ESMTP id 2lcWnLjEd85K; Tue, 5 Jan 2016 15:46:49 -0600 (CST)
Received: from localhost (localhost.localdomain [127.0.0.1])
by edge02.zimbra.com (Postfix) with ESMTP id D31B8A6287;
Tue, 5 Jan 2016 15:46:49 -0600 (CST)
DKIM-Filter: OpenDKIM Filter v2.10.3 edge02.zimbra.com D31B8A6287
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zimbra.com;
s=C2AA288C-EE47-11E2-9BB0-E820BDD9BDBF; t=1452030409;
bh=tF1L8aWTRVymRJMygqf2wu5UKPdonkNJBe5oSb/A/30=;
h=Date:From:To:Message-ID:MIME-Version;
b=U3SJAPJ1KU0VydPmk1oUuFPhS6hza8N1W4GQgHG7xeWWRcKdsPYssMh834EotnqKA
KaCkb+k+wHG0cXX/5q7BAflEhx37xQtVSuKfX//Go8SNN2/aI4OCyXOc9og4STFTo2
n6c6rW7+FInG9tGwtp2CRUx5pKGzJW5JBGPQgPcE=
X-Virus-Scanned: amavisd-new at edge02.zimbra.com
Received: from edge02.zimbra.com ([127.0.0.1])
by localhost (edge02.zimbra.com [127.0.0.1]) (amavisd-new, port 10026)
with ESMTP id 9fVWX8FF05TY; Tue, 5 Jan 2016 15:46:49 -0600 (CST)
Received: from [192.168.1.9] (unknown [75.111.52.177])
by edge02.zimbra.com (Postfix) with ESMTPSA id 53A0FA6283;
Tue, 5 Jan 2016 15:46:49 -0600 (CST)
Date: Tue, 05 Jan 2016 13:46:44 -0800
From: Quanah Gibson-Mount quanah@zimbra.com
To: Steve Jenkins steve@stevejenkins.com, Patrick Ben Koetter p@sys4.de
cc: opendkim-users@lists.opendkim.org
Subject: Re: How is LDAP used with OpenDKIM?
Message-ID: 1F356866AB87BD81ABDAA3A4@[192.168.1.9]
In-Reply-To: CAJTq_twSRX1PMz7bfdsX6up+Pv2DCbq1-i5Vdm-ujjbMSChoyw@mail.gmail.com
References: CAJTq_tx88KX5=BcYVicN1Z45JxYWUGXKWov2+QbLEzRmadMkJQ@mail.gmail.com
20160105204342.GB30056@sys4.de
CAJTq_twSRX1PMz7bfdsX6up+Pv2DCbq1-i5Vdm-ujjbMSChoyw@mail.gmail.com
X-Mailer: Mulberry/4.0.9a1 (Win32)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by mx.elandsys.com id u05LkvVP008879
X-archive-position: 3627
Sender: opendkim-users-bounce@lists.opendkim.org
List-Help: listria@lists.opendkim.org?Subject=help
List-Unsubscribe: opendkim-users-request@lists.opendkim.org?Subject=unsubscribe
List-Id: <opendkim-users.lists.opendkim.org>
List-Subscribe: opendkim-users-request@lists.opendkim.org?Subject=subscribe
List-Owner: listria+admin@lists.opendkim.org
List-Post: opendkim-users@lists.opendkim.org
X-list: opendkim-users</opendkim-users.lists.opendkim.org>
--On Tuesday, January 05, 2016 1:07 PM -0800 Steve Jenkins steve@stevejenkins.com wrote:
[Image:
"f18dQhb0S7ks8dDMPbW2n0x6l2B9gXrN7sKj6v4dZ2TMfD98PRrZF6W8rBqX01pctGFVXshw
p1k1H6H0"]On Tue, Jan 5, 2016 at 12:43 PM, Patrick Ben Koetter p@sys4.de wrote:
- Steve Jenkins steve@stevejenkins.com:
I don't use LDAP, so I'm not familiar with how to use it.
There's a discussion on the Postfix list currently about validating
relayers via LDAP queries, which got me wondering about what are the use
cases where OpenDKIM uses LDAP. Is it doing LDAP lookups to determins
whether certain messages should be signed? If not, what IS it doing (of
what CAN it do)?It queries a database via LDAP to find out if it should apply a DKIM
signature. If it should, it searches the database via LDAP for the DKIM
key(s).Simple enough! Thx, Patrick. :)
Download and install Zimbra, follow the DKIM wiki, and see? ;) We leverage OpenDKIM significantly for doing signing across multiple hosted domains, storing all the data in LDAP.
--Quanah