Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.300 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-14-2008, 12:41 PM
fobe's Avatar
Wizard
 
Join Date: Dec 2001
Posts: 511
Default [7.250] DKIM not working [NOTABUG]

Hi,
DKIM seems not to be working completelty. I have the following setup:
E-mail Security-> SMTP
1) Simple Mode
2) Routing: 1) mydomain.com
2) mailserver.mydomain.com
3)Relaying: Allowed hosts/networks-> mailserver.mydomain.com
4)Advanced: 1) Filled in my "Private RSA key"
filled in the selector "test1024"
DKIM Domains: mydomain.com
2) Activated "Use transparent mode" & "Allow SMTP traffic for listed hosts/nets"

Further I enabled & also disabeld the AV-footer, So I know for sure that the e-mail is going trough ASG.

My nameserver has the right entry (this is tested with another application where it works fine). The "public key" is added in the header but when I test with my yahoo-account it says the following:

"domainkeys=neutral (no sig)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mydomain.com; s=test1024; h=Fromate:To:Message-ID:Subject:
MIME-Version:Content-Type; bh=eYrTKD1FzeJ4fYijEdK/rdPnjLTnDVFszX
kas6BU55U=; b=J3Sg88eLzcfaEVuJpZqpxxWLryjd4fg7zJJgnEBmiFJu5gIk wd
JiVKW53sb9aUSyd84z9EZPDKShUxDK9ttTDY39bICkKnsyycG/ZfAonWTv25jzko
FhGZeQGEdPn57OrhQcCrQlza9HKp2buA+iXwy9mxspnltm8Eoh 8yx/WHI="

The domainkeys shouldn't be neutral (nosig) but something like: from=mydomain.com; domainkeys=pass (ok)...

Last edited by fobe; 07-14-2008 at 01:01 PM.
  #2 (permalink)  
Old 07-14-2008, 01:17 PM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,231
Default

Does the outgoing mail contain a DKIM-Signature header? Please send a message through that ASG to tkistner@astaro-tech.com (This is an out-of-band email address that does no content scan or modification on incoming messages).
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #3 (permalink)  
Old 07-14-2008, 02:16 PM
fobe's Avatar
Wizard
 
Join Date: Dec 2001
Posts: 511
Default

mail is sended
  #4 (permalink)  
Old 07-14-2008, 08:00 PM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,231
Default

This has resolved itself outside of this thread ...
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #5 (permalink)  
Old 09-12-2008, 12:39 AM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,385
Default Having a similar issue

Tom, I established a DKIM record at ns1.bluehost.com:
dkim._domainkey.mediasoftusa.com IN TXT v=DKIM1; p={output of OpenSSL stripped of header, footer & carriage returns}
I have pasted the output of OpenSSL for the private key into Private RSA key complete with the header, footer and CRs.

Key selector: dkim

Domain: mediasoftusa.com

The header of an email sent from mediasoftusa.com to yahoo.com reveals:
domainkeys=neutral (no sig)
Do I need to enable the transparent mode, or do I have another problem?

I have a two-page document I created entitled "Configuring DKIM in the Astaro SMTP Proxy" that I can send you if it would help you understand my problem.

Thanks - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!

Last edited by BAlfson; 09-12-2008 at 12:52 PM.
  #6 (permalink)  
Old 09-12-2008, 09:40 AM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,231
Default

Quote:
Originally Posted by BAlfson View Post
Tom, I established a DKIM record at ns1.bluehost.com:
dkim._domainkey.mediasoftusa.com IN TXT v=DKIM1; p={output of OpenSSL stripped of header, footer & carriage returns}
You also need to terminate the record name with a dot if you specify the full domain, like:

dkim._domainkey.mediasoftusa.com. IN TXT v=DKIM1; p={output of OpenSSL stripped of header, footer & carriage returns}

Quote:
Originally Posted by BAlfson View Post
The header of an email sent from mediasoftusa.com to yahoo.com reveals:
domainkeys=neutral (no sig)
This is a "domainkeys" result which is kind of a predecessor to DKIM. You can test using the "official" reflector address. See http://testing.dkim.org/reflector.html
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #7 (permalink)  
Old 09-12-2008, 12:56 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,385
Default

I'm sorry for the typo, Tom; the "." is in the DNS record.

An email to mail@testing.dkim.org returns an email containing:
Authentication Results
testing.dkim.org; v=0.1; ssp=neutral, header.From=balfson@MediaSoftUSA.com
DKIM Processing Output
[IIM-EOM: Info]
End of Message
Shouldn't there be something in my outbound header that indicates DKIM? Here's an example of what I sent to my Yahoo account:
From Bob Alfson Thu Sep 11 22:50:16 2008
Return-Path: <balfson@mediasoftusa.com>
Authentication-Results: mta293.mail.mud.yahoo.com from=MediaSoftUSA.com; domainkeys=neutral (no sig)
Received: from 68.15.104.33 (EHLO mediasoftusa.com) (68.15.104.33)
by mta293.mail.mud.yahoo.com with SMTP; Thu, 11 Sep 2008 15:51:26 -0700
Received: from BobDeskTop ([10.1.1.64]) by mediasoftusa.com with Microsoft SMTPSVC(6.0.3790.3959);
Thu, 11 Sep 2008 17:50:15 -0500
From: "Bob Alfson" <BAlfson@MediaSoftUSA.com>
To: <balfson@yahoo.com>
Subject: DKIM test
Date: Thu, 11 Sep 2008 17:50:16 -0500
Message-ID: <026FE3C15CAF0143A48A7A49428105BC4B0459@sun.MediaS oft.local>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0004_01C91436.D9302390"
Importance: Normal
Thread-Index: AckUYMGk9Z6xGeTESfuALLJfZiaGVQ==
Return-Path: BAlfson@MediaSoftUSA.com
Content-Length: 4132
Thanks again - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
  #8 (permalink)  
Old 09-12-2008, 07:32 PM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,231
Default

Yes, there should be a DKIM-Signature: header in there, so it doesn't sign it. Please check /var/log/smtp.log when sending a message. You can also send login info to tkistner@astaro.com, then I can have a look myself.
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
  #9 (permalink)  
Old 09-15-2008, 05:28 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,385
Default Almost there!

My mistake was diagnosed by Tom. His final email gave me what I was missing that caused the Astaro to reject emails from my Exchange Server:

Quote:
Re-add the smarthost to Exchange, and add the IP of your Exchange server to the "Relaying->Host-based relay" list. Then outgoing mail will be handled by ASG, and signing should work OK.
Now, my emails to myself at Gmail get through with a 'DKIM-pass' in the header and have the correct DKIM-Signature, but ones to my Yahoo account are not going through!

When I send an email to 'dkim-test@testing.dkim.org', I get:
Quote:
testing.dkim.org; v=0.1; dkim=fail, header.i=@mediasoftusa.com (
Err: body altered; RSA-64 err: hdrdiffs=none; bodyvfy=no; me
diasoftusa.com/dkim fail; );[/INDENT]
How can this be?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
  #10 (permalink)  
Old 09-15-2008, 06:13 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,385
Default

I found another reflector, and it passes me:

check-auth@verifier.port25.com

It's better than the one at dkim.org.


I'm still not able to send email to my Yahoo address.
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!

Last edited by BAlfson; 09-15-2008 at 06:26 PM.
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:23 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.