I'm implementing HTTP Message Signatures (RFC 9421) in Fedify, and although the signature base matches and the private–public key pair is correct, the signature verification keeps failing. I've wasted hours on this issue and still have no idea what's wrong. 😩
Hmm, test vectors for rsa-v1_5-sha256 made with httpsig.org seem something wrong…?
If you have a fediverse account, you can quote this note from your own instance. Search https://hollo.social/@hongminhee/0196aa3f-f881-7830-8568-d463c246182d on your instance and quote it. (Note that quoting is not supported in Mastodon.)