PHP生成DKIM密钥适配DNS提供商1024位RSA需求的问询
调整PHP代码生成1024位RSA的DKIM密钥
当前使用的PHP代码生成的是2048位RSA密钥搭配SHA256摘要的DKIM密钥,但DNS提供商仅支持1024位RSA密钥,以下是调整后的完整代码及关键说明:
<?php //Set these to match your domain and chosen DKIM selector $domain = 'example.com'; $selector = 'phpmailer'; //Private key filename for this selector $privatekeyfile = $selector . '_dkim_private.pem'; //Public key filename for this selector $publickeyfile = $selector . '_dkim_public.pem'; if (file_exists($privatekeyfile)) { echo "Using existing keys - if you want to generate new keys, delete old key files first.\n\n"; $privatekey = file_get_contents($privatekeyfile); $publickey = file_get_contents($publickeyfile); } else { //Create a 1024-bit RSA key with an SHA256 digest $pk = openssl_pkey_new( [ 'digest_alg' => 'sha256', 'private_key_bits' => 1024, // 关键修改:将密钥长度改为1024位 'private_key_type' => OPENSSL_KEYTYPE_RSA, ] ); //Save private key openssl_pkey_export_to_file($pk, $privatekeyfile); //Save public key $pubKey = openssl_pkey_get_details($pk); $publickey = $pubKey['key']; file_put_contents($publickeyfile, $publickey); $privatekey = file_get_contents($privatekeyfile); } echo "<pre>"."Private key (keep this private!):\n\n" . $privatekey; echo "\n\nPublic key:\n\n" . $publickey; //Prepare public key for DNS, e.g. //phpmailer._domainkey.example.com IN TXT "v=DKIM1; h=sha256; t=s; p=" "MIIBIjANBg...oXlwIDAQAB"... $dnskey = "$selector._domainkey.$domain IN TXT"; $dnsvalue = '"v=DKIM1; h=sha256; t=s; p=" '; //Some DNS servers don't like ;(semi colon) chars unless backslash-escaped $dnsvalue2 = '"v=DKIM1\; h=sha256\; t=s\; p=" '; //Strip and split the key into smaller parts and format for DNS //Many DNS systems don't like long TXT entries //but are OK if it's split into 255-char chunks //Remove PEM wrapper $publickey = preg_replace('/^-+.*?-+$/m', '', $publickey); //Strip line breaks $publickey = str_replace(["\r", "\n"], '', $publickey); //Split into chunks $keyparts = str_split($publickey, 253); //Becomes 255 when quotes are included //Quote each chunk foreach ($keyparts as $keypart) { $dnsvalue .= '"' . trim($keypart) . '" '; $dnsvalue2 .= '"' . trim($keypart) . '" '; } echo "\n\nDNS key:\n\n" . trim($dnskey); echo "\n\nDNS value:\n\n" . trim($dnsvalue); echo "\n\nDNS value (with escaping):\n\n" . trim($dnsvalue2); ?>
关键修改说明
- 核心调整:在
openssl_pkey_new的配置数组中,将private_key_bits的值从2048改为1024,直接生成符合DNS提供商要求的1024位RSA密钥。 - 前置操作:运行修改后的代码前,必须删除之前生成的
phpmailer_dkim_private.pem和phpmailer_dkim_public.pem文件,否则代码会优先使用已存在的2048位密钥。 - SHA256摘要保留:
digest_alg设置为sha256是邮件签名的哈希算法,与密钥长度无关,无需修改,DKIM协议支持1024位RSA搭配SHA256签名。
内容的提问来源于stack exchange,提问作者Abhinav
相关产品推荐
相关产品推荐

