RFC 9421 signatures are verified, not refused
WordPress's ActivityPub plugin (and Ghost and Fedify) sign with RFC 9421 first and fall back to draft-cavage only after a refusal, so each first delivery cost two requests and a 401 in our statistics. Now a request carrying Signature-Input is verified as an HTTP message signature: its covered components (the method and our own public target, the body's Content-Digest), its created and expires, with the actor's RSA key under PKCS#1 v1.5 or PSS. Deliveries and signed fetches both take it; the ledger names the scheme (rfc9421:rsa-v1_5-sha256). What PrivaPub sends stays draft-cavage, which every server reads. Ed25519 waits for FEP-521a keys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
26dac40720
commit
c5a69d240a
10 files changed
+423
-30
No files matched your search
+2
-1
@@ -638,7 +638,8 @@ it, raw where it doesn't.
|
||||
|
||||
#### P8 Signatures, discovery and the long tail
|
||||
- **Signatures:**
|
||||
- RFC 9421 inbound (RSA and Ed25519, Content-Digest);
|
||||
- RFC 9421 inbound (RSA and Ed25519, Content-Digest): **RSA done 2026-10-05** (PKCS#1 v1.5 and PSS, Content-Digest,
|
||||
deliveries and signed fetches); Ed25519 waits for FEP-521a keys;
|
||||
- outbound double-knock, remembered per host;
|
||||
- `publicKey` arrays and FEP-521a Multikey;
|
||||
- FEP-8b32 proof verification;
|
||||
|
||||
Reference in new issue
Block a user