mirror of
https://github.com/KumoCorp/kumomta.git
synced 2026-09-08 16:01:19 +00:00
The signer cache maps the signer parameters to a pre-made signing context. It is essentially a map of (domain, key) -> signer. Assuming that the (domain,key) tuple is unique, then this is a good, effective use of that cache. However, if multiple domains can share the same key then we can end up re-parsing the same key data for each of them, which is moderately expensive and a waste of CPU. This commit introduces an additional cache for the key source to the resultant compiled key. This allows sharing of the same compiled key across signing parameters that otherwise vary, and should help to shave off some latency.
kumo-dkim
DKIM (RFC6376) implementation
Features
Verifying email signatures
Example:
let res: DKIMResult = kumo_dkim::verify_email(&from_domain, &parsed_email).await?;
if let Some(err) = &res.error() {
error!(logger, "dkim verify fail: {}", err);
}
println!("dkim={}", res.with_detail());
Signing an email
Example:
let private_key =
rsa::RsaPrivateKey::read_pkcs1_pem_file(Path::new("./test/keys/2022.private"))?;
let signer = SignerBuilder::new()
.with_signed_headers(["From", "Subject"])?
.with_private_key(private_key)
.with_selector("2020")
.with_signing_domain("example.com")
.build()?;
let signature = signer.sign(&email)?;
println!("{}", signature); // DKIM-Signature: ...
See the SignerBuilder object documentation for more information.
Generate a test DKIM key
Using OpenDKIM:
opendkim-genkey \
--testmode \
--domain=example.com \
--selector=2022 \
--nosubdomains