<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Using DKIM in Exim</title>
	<atom:link href="http://mikepultz.com/2010/02/using-dkim-in-exim/feed/" rel="self" type="application/rss+xml" />
	<link>http://mikepultz.com/2010/02/using-dkim-in-exim/</link>
	<description>personal and professional blog of mike pultz, technology specialist and serial entrepreneur;</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:39:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: John</title>
		<link>http://mikepultz.com/2010/02/using-dkim-in-exim/comment-page-1/#comment-203</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 20 Jun 2010 06:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://mikepultz.com/?p=384#comment-203</guid>
		<description>Hi Mike,

Thanks for this great topic, I did that but I got permerror (key failed) for dkim and no sig for domainkeys.

Authentication-Results: mta1045.mail.sk1.yahoo.com from=developers-heaven.net; domainkeys=neutral (no sig); from=developers-heaven.net; dkim=permerror (key failed) 

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=developers-heaven.net; s=x; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Message-ID:Date:Subject:To:From; bh=dZwg0roqeT4Z81/Gk6beBXednOetUVdfKD0HSi0smMw=; b=iwjc2Fu7aQAZ3nSb9Asu1DaPh27Lut0Ig2xEZ9FS5Frwnq57fJa8Vo4iaOKu/RokAIDVtgMUtZoh0JyBlpG18yJJILwuPO4ORzstS/fP9EGxfyLZBDZLtcSQOFRhc/dr; 

DKIM check details:
———————————————————-
Result: permerror (invalid key: error reading public key: 3071417264:error:0D07209B:asn1 encoding routines:ASN1_get_object:too long:asn1_lib.c:142:;3071417264:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object header:tasn_dec.c:1281:;3071417264:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:380:Type=X509_PUBKEY;)

May you please guide me how to fix.</description>
		<content:encoded><![CDATA[<p>Hi Mike,</p>
<p>Thanks for this great topic, I did that but I got permerror (key failed) for dkim and no sig for domainkeys.</p>
<p>Authentication-Results: mta1045.mail.sk1.yahoo.com from=developers-heaven.net; domainkeys=neutral (no sig); from=developers-heaven.net; dkim=permerror (key failed) </p>
<p>DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=developers-heaven.net; s=x; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Message-ID:Date:Subject:To:From; bh=dZwg0roqeT4Z81/Gk6beBXednOetUVdfKD0HSi0smMw=; b=iwjc2Fu7aQAZ3nSb9Asu1DaPh27Lut0Ig2xEZ9FS5Frwnq57fJa8Vo4iaOKu/RokAIDVtgMUtZoh0JyBlpG18yJJILwuPO4ORzstS/fP9EGxfyLZBDZLtcSQOFRhc/dr; </p>
<p>DKIM check details:<br />
———————————————————-<br />
Result: permerror (invalid key: error reading public key: 3071417264:error:0D07209B:asn1 encoding routines:ASN1_get_object:too long:asn1_lib.c:142:;3071417264:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object header:tasn_dec.c:1281:;3071417264:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:380:Type=X509_PUBKEY;)</p>
<p>May you please guide me how to fix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Exim smarthost with DKIM</title>
		<link>http://mikepultz.com/2010/02/using-dkim-in-exim/comment-page-1/#comment-186</link>
		<dc:creator>Exim smarthost with DKIM</dc:creator>
		<pubDate>Thu, 13 May 2010 10:14:15 +0000</pubDate>
		<guid isPermaLink="false">http://mikepultz.com/?p=384#comment-186</guid>
		<description>[...] Never mind - I found some info. I just had a lapse in my search-fu.  This page has what I need: http://mikepultz.com/2010/02/using-dkim-in-exim/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Never mind &#8211; I found some info. I just had a lapse in my search-fu.  This page has what I need: <a href="http://mikepultz.com/2010/02/using-dkim-in-exim/" rel="nofollow">http://mikepultz.com/2010/02/using-dkim-in-exim/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://mikepultz.com/2010/02/using-dkim-in-exim/comment-page-1/#comment-185</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Wed, 12 May 2010 17:37:22 +0000</pubDate>
		<guid isPermaLink="false">http://mikepultz.com/?p=384#comment-185</guid>
		<description>&lt;a href=&quot;#comment-184&quot; rel=&quot;nofollow&quot;&gt;@Beau&lt;/a&gt; 

Hey Beau,

I&#039;m not 100% familiar with the Debian install; it seems to break the file up into components- usually I install from source and have just one big configure file- but this looks like the right spot.

1) That should be all you need to at least sign out-going messages.

2) Yup, the selector is just a random word that is specified in your config; it uses this word to do the DNS lookup against your domain- most of the time it&#039;s kept really short (like a single character), but as long as it&#039;s a valid hostname, it&#039;s fine.

3) Yes, that&#039;s the full path to the private key; so in your example, your private key would have to be in /- is that correct? maybe it&#039;s not signing your e-mails because it can&#039;t find the key?

Also, have you confirmed that messages are being sent through exim? can you see messages coming in/out in your main exim log file?

Mike</description>
		<content:encoded><![CDATA[<p><a href="#comment-184" rel="nofollow">@Beau</a> </p>
<p>Hey Beau,</p>
<p>I&#8217;m not 100% familiar with the Debian install; it seems to break the file up into components- usually I install from source and have just one big configure file- but this looks like the right spot.</p>
<p>1) That should be all you need to at least sign out-going messages.</p>
<p>2) Yup, the selector is just a random word that is specified in your config; it uses this word to do the DNS lookup against your domain- most of the time it&#8217;s kept really short (like a single character), but as long as it&#8217;s a valid hostname, it&#8217;s fine.</p>
<p>3) Yes, that&#8217;s the full path to the private key; so in your example, your private key would have to be in /- is that correct? maybe it&#8217;s not signing your e-mails because it can&#8217;t find the key?</p>
<p>Also, have you confirmed that messages are being sent through exim? can you see messages coming in/out in your main exim log file?</p>
<p>Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beau</title>
		<link>http://mikepultz.com/2010/02/using-dkim-in-exim/comment-page-1/#comment-184</link>
		<dc:creator>Beau</dc:creator>
		<pubDate>Mon, 10 May 2010 19:00:12 +0000</pubDate>
		<guid isPermaLink="false">http://mikepultz.com/?p=384#comment-184</guid>
		<description>Thanks a bunch for this great tutorial. I have a couple questions though. For starters, I&#039;m on Debian and Nginx and I installed exim with this command: &quot;apt-get -t lenny-backports install exim4&quot; which installed version 4.71. I then followed your tutorial for signing emails but my emails still don&#039;t get signed. Step 1 seems to have gone off without a hitch as I can verify that both those files now exist and have data that looks right.

I added the following lines to /etc/exim4/conf.d/transport/30_exim4-config_remote_smtp under driver = smtp: 
  dkim_domain = dostuffright.com
  dkim_selector = whizbang-dkim
  dkim_private_key = /dkim.private.key
  dkim_canon = relaxed

And restarted exim. I then added the txt record to my domain as you instructed. The problem is that my emails don&#039;t seem to be getting signed. I&#039;ve tried looking at the raw headers and sending emails to six different rotator services and I&#039;m quite positive my emails aren&#039;t getting signed. So my questions are:

1) Is there something I need to do to turn signing on besides adding those lines to that file?
2) What is the &quot;selector&quot;? Is it just some random word that has to be in both the header and the txt record?
3) Is dkim_private_key just the path to the dkim public key on my server? That&#039;s what I&#039;m assuming it is.

Thanks a bunch!
Beau</description>
		<content:encoded><![CDATA[<p>Thanks a bunch for this great tutorial. I have a couple questions though. For starters, I&#8217;m on Debian and Nginx and I installed exim with this command: &#8220;apt-get -t lenny-backports install exim4&#8243; which installed version 4.71. I then followed your tutorial for signing emails but my emails still don&#8217;t get signed. Step 1 seems to have gone off without a hitch as I can verify that both those files now exist and have data that looks right.</p>
<p>I added the following lines to /etc/exim4/conf.d/transport/30_exim4-config_remote_smtp under driver = smtp:<br />
  dkim_domain = dostuffright.com<br />
  dkim_selector = whizbang-dkim<br />
  dkim_private_key = /dkim.private.key<br />
  dkim_canon = relaxed</p>
<p>And restarted exim. I then added the txt record to my domain as you instructed. The problem is that my emails don&#8217;t seem to be getting signed. I&#8217;ve tried looking at the raw headers and sending emails to six different rotator services and I&#8217;m quite positive my emails aren&#8217;t getting signed. So my questions are:</p>
<p>1) Is there something I need to do to turn signing on besides adding those lines to that file?<br />
2) What is the &#8220;selector&#8221;? Is it just some random word that has to be in both the header and the txt record?<br />
3) Is dkim_private_key just the path to the dkim public key on my server? That&#8217;s what I&#8217;m assuming it is.</p>
<p>Thanks a bunch!<br />
Beau</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://mikepultz.com/2010/02/using-dkim-in-exim/comment-page-1/#comment-177</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Sun, 07 Mar 2010 18:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://mikepultz.com/?p=384#comment-177</guid>
		<description>&lt;a href=&quot;#comment-173&quot; rel=&quot;nofollow&quot;&gt;@mike&lt;/a&gt; 
Thanks. I am using the same domain/selector and getting a &quot;pass&quot; from check-auth@verifier.port25.com for &quot;DKIM check&quot; for all domains.

Again, thanks for the excellent tutorial.</description>
		<content:encoded><![CDATA[<p><a href="#comment-173" rel="nofollow">@mike</a><br />
Thanks. I am using the same domain/selector and getting a &#8220;pass&#8221; from <a href="mailto:check-auth@verifier.port25.com">check-auth@verifier.port25.com</a> for &#8220;DKIM check&#8221; for all domains.</p>
<p>Again, thanks for the excellent tutorial.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
