OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: PIX header truncation (was: pix workaround broken)

From: Mark Martinec (Mark.Martinec+postfixijs.si)
Date: Tue Jul 24 2007 - 07:13:18 CDT


> * Wietse Venema <wietseporcupine.org>:
> > - Update the smtp_header_out() routine to insert a null terminator
> > into lines that exceed some pre-defined length (255?). The
> > "context" is a pointer to the SMTP_STATE structure with the bit
> > flags.
>
> But where IS the limit? Or should it be configurable as well?

It would be really nice if someone with a good Cisco relationship
or at least an effective support contract covering PIX would
find out what exactly is the problem. I heard rumors that
DKIM signatures can indeed cause PIX to disconnect, but I don't
know what aspect of the header field is problematic, and which
versions of PIX are brooken.

Finding what a CSCsg52277 bug is exactly, could be a good start.

It is ironic that Cisco is one of the main supporters of DKIM :)

  Mark