@renchap@oisaur.com how does RFC9421 differ from Mastodon's existing support for HTTP Signatures?

Does this mean you're moving away from cavage-12? That's important to know, and if you're looking for an implementor to handle double-knocking, that is something I can put together for you.. we don't do it at current.

@julian I will need to ping @daveDavid Roetzel here as he is the one working on it, but yes we want to move away from cavage-12 and use the final RFC.

Our plan is to support validating RFC9421-final signatures in our next release, then do double-knocking (with RFC9421 first and a cache of what signature to use) in the following release.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://oisaur.com/users/renchap/statuses/114455597139468566 on your instance and quote it. (Note that quoting is not supported in Mastodon.)