Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

NodeBB

  1. Home
  2. General Discussion
  3. Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

Scheduled Pinned Locked Moved General Discussion
activitypubfedidevrfc9421
16 Posts 6 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • julian@fietkau.socialJ This user is from outside of this forum
    julian@fietkau.socialJ This user is from outside of this forum
    julian@fietkau.social
    wrote last edited by
    #1

    RE: https://mastodon.social/@bagder/116359048796181736

    Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

    On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

    Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    #ActivityPub #FediDev #RFC9421

    julian@activitypub.spaceJ gabboman@gabboman.xyzG hazelnoot@void.lgbtH 3 Replies Last reply
    1
    0
    • tag-activitypub@relay.fedi.buzzT tag-activitypub@relay.fedi.buzz shared this topic
    • mradcliffe@nokoto.orgM This user is from outside of this forum
      mradcliffe@nokoto.orgM This user is from outside of this forum
      mradcliffe@nokoto.org
      wrote last edited by
      #2

      Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

      The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

      I should probably check again...

      1 Reply Last reply
      1
      0
      • julian@fietkau.socialJ julian@fietkau.social

        RE: https://mastodon.social/@bagder/116359048796181736

        Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

        On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

        Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

        #ActivityPub #FediDev #RFC9421

        julian@activitypub.spaceJ This user is from outside of this forum
        julian@activitypub.spaceJ This user is from outside of this forum
        julian@activitypub.space
        wrote last edited by
        #3

        @julian@fietkau.social by "can't handle" do you mean "still reliant on cavage-12"?

        🙋‍♂️

        1 Reply Last reply
        0
        • julian@fietkau.socialJ This user is from outside of this forum
          julian@fietkau.socialJ This user is from outside of this forum
          julian@fietkau.social
          wrote last edited by
          #4

          @julian@activitypub.space As I understand the migration path, it's like

          1. Able to receive RFC 9421 in addition to draft-cavage
          2. Able to send RFC 9421 in addition to draft-cavage
          3. Send RFC 9421 by default, but be able to fall back to draft-cavage if needed

          So by “can't handle” I meant step 1. 🙂 Although the unspoken step 4 is to remove draft-cavage support once everyone else has taken step 1, I'm ultimately also wondering when we'll get there.

          evan@cosocial.caE julian@activitypub.spaceJ 2 Replies Last reply
          1
          • julian@fietkau.socialJ julian@fietkau.social

            @julian@activitypub.space As I understand the migration path, it's like

            1. Able to receive RFC 9421 in addition to draft-cavage
            2. Able to send RFC 9421 in addition to draft-cavage
            3. Send RFC 9421 by default, but be able to fall back to draft-cavage if needed

            So by “can't handle” I meant step 1. 🙂 Although the unspoken step 4 is to remove draft-cavage support once everyone else has taken step 1, I'm ultimately also wondering when we'll get there.

            evan@cosocial.caE This user is from outside of this forum
            evan@cosocial.caE This user is from outside of this forum
            evan@cosocial.ca
            wrote last edited by
            #5

            @julian@fietkau.social @julian@activitypub.space Honestly, I think it's going to be a while.

            I think the term for step 3 is "double knocking", and it's called out in the HTTP Signature report for the Social CG:

            https://swicg.github.io/activitypub-http-signature/

            1 Reply Last reply
            1
            • julian@fietkau.socialJ julian@fietkau.social

              RE: https://mastodon.social/@bagder/116359048796181736

              Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

              On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

              Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

              #ActivityPub #FediDev #RFC9421

              gabboman@gabboman.xyzG This user is from outside of this forum
              gabboman@gabboman.xyzG This user is from outside of this forum
              gabboman@gabboman.xyz
              wrote last edited by
              #6

              @fedify@hollo.social @julian@fietkau.social

              I still cant! but I wonder, any example of a software in node/javascript that uses the new signature standard?

              1 Reply Last reply
              0
              • julian@fietkau.socialJ This user is from outside of this forum
                julian@fietkau.socialJ This user is from outside of this forum
                julian@fietkau.social
                wrote last edited by
                #7

                @gabboman @fedify Fedify does it in TypeScript, as for vanilla JavaScript I have no idea.

                gabboman@gabboman.xyzG 1 Reply Last reply
                1
                • julian@fietkau.socialJ julian@fietkau.social

                  @gabboman @fedify Fedify does it in TypeScript, as for vanilla JavaScript I have no idea.

                  gabboman@gabboman.xyzG This user is from outside of this forum
                  gabboman@gabboman.xyzG This user is from outside of this forum
                  gabboman@gabboman.xyz
                  wrote last edited by
                  #8

                  @fedify@hollo.social @julian@fietkau.social

                  excelent

                  1 Reply Last reply
                  1
                  • mradcliffe@nokoto.orgM This user is from outside of this forum
                    mradcliffe@nokoto.orgM This user is from outside of this forum
                    mradcliffe@nokoto.org
                    wrote last edited by
                    #9

                    @evan @julian@fietkau.social @julian@activitypub.space  I think organizing a contribution event to refactor @peertube/http-signature and golang’s httpsig or gotosocial's fork of httpsig to support both cavage-12 and RFC9421 would go a long way to getting this done sooner as most of the software missing implementation depend on those libraries.

                    evan@cosocial.caE 1 Reply Last reply
                    0
                    • mradcliffe@nokoto.orgM mradcliffe@nokoto.org

                      @evan @julian@fietkau.social @julian@activitypub.space  I think organizing a contribution event to refactor @peertube/http-signature and golang’s httpsig or gotosocial's fork of httpsig to support both cavage-12 and RFC9421 would go a long way to getting this done sooner as most of the software missing implementation depend on those libraries.

                      evan@cosocial.caE This user is from outside of this forum
                      evan@cosocial.caE This user is from outside of this forum
                      evan@cosocial.ca
                      wrote last edited by
                      #10

                      @mradcliffe The thing about double-knocking is that it requires two implementations (RFC 9421, draft-cavage-12). It also requires a persistent cache, so once you figure out which signature system the remote server supports, you only use that one -- you don't double-knock every time. It might not work as a library.

                      mradcliffe@nokoto.orgM 1 Reply Last reply
                      0
                      • julian@activitypub.spaceJ This user is from outside of this forum
                        julian@activitypub.spaceJ This user is from outside of this forum
                        julian@activitypub.space
                        wrote last edited by
                        #11

                        @gabboman@gabboman.xyz are you coding typescript?

                        NodeBB is plain js. C'mon you don't need type safety. Code like its the 2000s.

                        1 Reply Last reply
                        0
                        • julian@fietkau.socialJ julian@fietkau.social

                          RE: https://mastodon.social/@bagder/116359048796181736

                          Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

                          On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

                          Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

                          #ActivityPub #FediDev #RFC9421

                          hazelnoot@void.lgbtH This user is from outside of this forum
                          hazelnoot@void.lgbtH This user is from outside of this forum
                          hazelnoot@void.lgbt
                          wrote last edited by
                          #12

                          Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

                          @julian@fietkau.social @fedify@hollo.social I'm honestly not aware of any that do support it yet...

                          julian@fietkau.socialJ 1 Reply Last reply
                          0
                          • julian@fietkau.socialJ julian@fietkau.social

                            @julian@activitypub.space As I understand the migration path, it's like

                            1. Able to receive RFC 9421 in addition to draft-cavage
                            2. Able to send RFC 9421 in addition to draft-cavage
                            3. Send RFC 9421 by default, but be able to fall back to draft-cavage if needed

                            So by “can't handle” I meant step 1. 🙂 Although the unspoken step 4 is to remove draft-cavage support once everyone else has taken step 1, I'm ultimately also wondering when we'll get there.

                            julian@activitypub.spaceJ This user is from outside of this forum
                            julian@activitypub.spaceJ This user is from outside of this forum
                            julian@activitypub.space
                            wrote last edited by
                            #13

                            @julian@fietkau.social ah, then no, NodeBB has no support yet. That's true though that there is a step-wise upgrade pattern.

                            Updating our HTTP Signature lib is part of our grant funded work so it'll get sorted out soon!

                            cc @evan@cosocial.ca @gabboman@gabboman.xyz

                            1 Reply Last reply
                            1
                            • evan@cosocial.caE evan@cosocial.ca

                              @mradcliffe The thing about double-knocking is that it requires two implementations (RFC 9421, draft-cavage-12). It also requires a persistent cache, so once you figure out which signature system the remote server supports, you only use that one -- you don't double-knock every time. It might not work as a library.

                              mradcliffe@nokoto.orgM This user is from outside of this forum
                              mradcliffe@nokoto.orgM This user is from outside of this forum
                              mradcliffe@nokoto.org
                              wrote last edited by
                              #14

                              @evan Thanks for the response. I think how a given software does double-knocking is up to that software. It is not necessarily true that you have to store the result, but it is ideal. I am much too lazy to refactor a persistent cache and I just double-knock every time. 😛

                              But to start, those libraries need to be able to support both signature implementations as those libraries are already in-use by the majority of software that has not implemented RFC 9421 yet.

                              1 Reply Last reply
                              1
                              • evan@cosocial.caE This user is from outside of this forum
                                evan@cosocial.caE This user is from outside of this forum
                                evan@cosocial.ca
                                wrote last edited by
                                #15

                                @gabboman @fedify @julian I'm adding it to activitypub-bot this week. I'll send a link when it's up.

                                1 Reply Last reply
                                0
                                • hazelnoot@void.lgbtH hazelnoot@void.lgbt

                                  Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

                                  @julian@fietkau.social @fedify@hollo.social I'm honestly not aware of any that do support it yet...

                                  julian@fietkau.socialJ This user is from outside of this forum
                                  julian@fietkau.socialJ This user is from outside of this forum
                                  julian@fietkau.social
                                  wrote last edited by
                                  #16

                                  @hazelnoot @fedify At the very least, Mastodon and Fedify (and by extension Hollo and Ghost) do. Outside of those I'm very unsure! I've seen @silverpill talk about it a bunch, so maybe Mitra supports it as well.

                                  1 Reply Last reply
                                  0

                                  Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                  Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                  With your input, this post could be even better 💗

                                  Register Login
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Don't have an account? Register

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups