Last Call Review of draft-kucherawy-authres-header-b-
Nice little document. (Which is much better than a nice
I see no substantive security issues here.
Two nits below. I've no real problem if they're ignored.
1. What if someone defines a MACing scheme for DKIM with
a teensy-weensy MAC? There might be no way to get 8
characters then. Suggest allowing the full authenticator
in that case if its <8 bytes long. Very unlikely but
maybe worth a sentence.
2. Apppendix A says:
"Presumably due to a change in one of the five header fields covered
by the two signatures, the former signature failed to verify while
the latter passed."
I think that could only happen if they use different c14n, if
so maybe say so. Or could be better to say the results may
differ due for key mgmt reasons (e.g. an inaccessible public key)
or because the signature values have been corrupted. Reason to
prefer those is that they're more likely. (Or am I missing