Originally submitted by josephheenan (Joseph Heenan) on 2023-02-15
As Justin brought up on today’s call, there is an issue with the way we use http sig:
https://lists.w3.org/Archives/Public/ietf-http-wg/2023JanMar/0063.html
in particular this text from FAPI2 Message Signing:
1. shall cryptographically link the response to the request by including the request signature in the response signature input by means of the `req` boolean flag defined in 2.4 in [!I-D.ietf-httpbis-message-signatures] on the signature field of the request that caused the response
Bitbucket status: resolved
Bitbucket origin: issue 575
As Justin brought up on today’s call, there is an issue with the way we use http sig:
https://lists.w3.org/Archives/Public/ietf-http-wg/2023JanMar/0063.html
in particular this text from FAPI2 Message Signing:
1. shall cryptographically link the response to the request by including the request signature in the response signature input by means of the `req` boolean flag defined in 2.4 in [!I-D.ietf-httpbis-message-signatures] on the signature field of the request that caused the response
Bitbucket status: resolved
Bitbucket origin: issue 575