Cisco Cisco Email Security Appliance C390 기술 참조

다운로드
페이지 326
 
3-34
CLI Reference Guide for AsyncOS 9.8 for Cisco Email Security Appliances
 
Chapter 3      The Commands: Reference Examples
  Domain Keys
Note
For enhanced security, if encryption of sensitive data in the appliance is enabled in FIPS mode, you will 
not be able view the private key. If you intend to edit the private key, you can enter an existing private 
key or generate a new private key.
Batch Format - Signing Profiles
The batch format of the 
domainkeysconfig
 command can be used to create, edit, or delete signing 
profiles 
Adding a DomainKeys/DKIM signing profile:
domainkeysconfig profiles signing new <name> <type> <domain> 
<selector> <user-list> [options]
Table 3-1
domainkeysconfig New Signing Profile Arguments
Argument
Description
<name>
Name of domain profile.
<type>
Type of domain.  Can be 
dk
 or 
dkim
.
<domain>
Domain field of domain profile.  This forms the 
d
 tag 
of the Domain-Keys signature.
<selector>
Selector field of domain profile.  This forms the 
s
 tag 
of the Domain-Keys signature.
<user-list>
Comma separated list of domain profile users.  Users 
are used to match against email addresses to 
determine if a specific domain profile should be used 
to sign an email. Use the special keyword 
all
 to 
match all domain users.
[options]
--key_name
The name of the private key that will be used for 
signing.
--canon
The canonicalization algorithm to use when signing 
by DK. Currently supported algorithms are 
simple
 
and 
nofws
. Default is 
nofws
.
--body_canon
The body canonicalization algorithm of to use when 
signing by DKIM.  Currently supported algorithms 
are 
simple
 and 
relaxed
. Default is 
simple
.
--header_canon
The headers canonicalization algorithm of to use 
when signing by DKIM.  Currently supported 
algorithms are 
simple
 and 
relaxed
. Default is 
simple
.
--body_length
Number of bytes of canonicalized body that are used 
to calculate the signature.  Is used only in DKIM 
profiles.  If used this value becomes 
l
 tag of the 
signature.  By default it is not used.