From: Charles Lindsey (chl@clw.cs.man.ac.uk)
Date: Mon Jun 07 1999 - 06:22:26 CDT
In <19990604120344.34847@main.templetons.com> Brad Templeton <brad@templetons.com> writes:
>However, it should never be specified that checking the body hash is an
>OPTION. If the body is meaningful, you can't claim to have checked the
>signature if you didn't check the body hash.
I would agree that, if a Content-MD5 header is present, then all reading
agents SHOULD check it and report. We could write this into the Mime
section of our Draft.
I have a particularly stupid MUA (dtmail) that generates the Content-MD5
header, but does not check it :-( .
-- Charles H. Lindsey ---------At Home, doing my own thing------------------------ Email: chl@clw.cs.man.ac.uk Web: http://www.cs.man.ac.uk/~chl Voice/Fax: +44 161 437 4506 Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K. PGP: 2C15F1A9 Fingerprint: 73 6D C2 51 93 A0 01 E7 65 E8 64 7E 14 A4 AB A5