I (hopefully) made some progress regarding HTTPS signature handling and double-knocking.
-
I (hopefully) made some progress regarding HTTPS signature handling and double-knocking.
Current default is to first try draft-cavage-http-signatures-12, then RFC 9421: HTTP Message Signatures. This may be changed later.
Retry (the second knock) is done, if the first results in a 400, 401 or 403.
If the peer instance has accepted DC12 in the past, the double-knocking will use DC12 first, then RFC9421.
If the peer instance has accepted RFC9421 in the past, the double-knocking will use RFC9421 first, then DC12.
-
I (hopefully) made some progress regarding HTTPS signature handling and double-knocking.
Current default is to first try draft-cavage-http-signatures-12, then RFC 9421: HTTP Message Signatures. This may be changed later.
Retry (the second knock) is done, if the first results in a 400, 401 or 403.
If the peer instance has accepted DC12 in the past, the double-knocking will use DC12 first, then RFC9421.
If the peer instance has accepted RFC9421 in the past, the double-knocking will use RFC9421 first, then DC12.
@nick@mammuthus.de shouldn't the double knock be 9421 first, and then cavage-12 on failure?
Also cool! I'd love to test NodeBB's implementation against it. <img class="not-responsive emoji" src="/emoji/ap/smile/activitypub.space" title="
" /> -
? [[global:guest]] crossposted this topic to General Discussion
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login