Project

General

Profile

Actions

Task #6625

closed

Fix our dkim setup

Added by Nico Schottelius about 5 years ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Target version:
-
Start date:
04/25/2019
Due date:
05/02/2019
% Done:

90%

Estimated time:
PM Check date:
04/28/2019

Description

From: Maximilian Eschenbacher <maximilian@XXX>
To: info@ungleich.ch
Subject: DKIM verification failure on ungleich.ch
Flags: seen, signed
Date: Mon 22 Apr 2019 10:21:13 PM CEST
Maildir: /ungleich/inbox
Attachments: [1]1.msgpart(358)
Signature: unverified (Details)

Hey there!

I've recently reconfigured my mail setup an noticed a DKIM verification
failure in my logs for a mail to the bird-users-ML and though I'd give
you a heads up:

Apr 20 18:55:27 qadesch opendkim[24840]: 9AB3215F613: key retrieval failed (s=mail, d=ungleich.ch): 'mail._domainkey.ungleich.ch' record not found

Best regards

Maximilian Eschenbacher
Actions #1

Updated by Jason Kim almost 5 years ago

  • PM Check date set to 04/28/2019
Actions #2

Updated by Jin-Guk Kwon almost 5 years ago

it looks like DKIM is disabled.

- it is disabled in cdist type

In __ungleich_mx_primary/manifest

# Enable OpenDKIM
#__ungleich_opendkim

- there are no TXT record.
no TXT record in zone files

mail._domainkey    IN    TXT    ( "v=DKIM1; k=rs

Actions #3

Updated by Nico Schottelius almost 5 years ago

First check whether the entries are in DNS - I am not sure whether they
are correctly added at the moment

writes:

Actions #4

Updated by Mirjana Rupar almost 5 years ago

Jin-Guk, update the status of the task and comment, please.

Actions #5

Updated by Nico Schottelius almost 5 years ago

  • Project changed from 45 to queue
  • Description updated (diff)
  • Assignee deleted (Jin-Guk Kwon)

queued

Actions #6

Updated by Jin-Guk Kwon over 4 years ago

  • Status changed from New to Feedback
  • Assignee set to Nico Schottelius
  • % Done changed from 0 to 90

1. recreate DKIM Key for ungleich.ch

2. update /etc/opendkim.conf file
- add Domain, Selector, Socket

3. update /etc/default/opendkim file

4. updated DNS Record on DNS server
- updated zone file

5. run DNS cdist

6. test DKIM
- http://www.mail-tester.com --> DKIM pass
- https://www.appmaildev.com/en/dkim --> pass

7. update _ungleich_opendkim cdist
- update dot-cdist/files/dkim_domain_keys/ungleich.ch/mail.private
- update dot-cdist/files/dkim_domain_keys/ungleich.ch/mail.txt
- update dot-cdist/type/
_ungleich_opendkim/files/opendkim.conf
- update dot-cdist/type/__ungleich_opendkim/files/defaults

Actions #7

Updated by Nico Schottelius 4 months ago

  • Status changed from Feedback to Closed
Actions

Also available in: Atom PDF