-
Notifications
You must be signed in to change notification settings - Fork 20
Open
Description
In the latest draft, the spec uses tags in all the headers (sig2=)
Signature-Agent: sig2="https://signature-agent.test"
Signature-Input: sig2=("@authority" "signature-agent";key="sig2")\
;created=1735689600\
;keyid="oD0HwocPBSfpNy5W3bpJeyFGY_IQ_YpqxSjQ3Yd-CLA"\
;alg="rsa-pss-sha512"\
;expires=1735693200\
;nonce="XSHtZVCThSIAksXsH9WBs6AtxtXC0eQGiIcUGSoJstFs8lAWakjhrfwzLhyjtme5iXMZvmFWqDEs6cT3Jf+BbQ=="\
;tag="web-bot-auth"
Signature: sig2=:I1QWNzGXdP1a4dSvOHLCVOOanEYHDk+ZsVxM9MLX/p4ko69ghKwR5EOtAD96g7g4GWP7lmpM/jFAf9q8EFRDTPLjUXySwMv4YPgabv2LQihTJG2y8a2m6IGltyruwQNiqSJVUuRaG9+b17CGmAMFZh30X6GXLdQJrCARpeTqPwp2DC+a8haDE/VE5EruqzjA5/2mKwvrkzkSqeW5tOVtFwWRRHIOidquf/8Je6kM9mhgkg4arudLA5SL4wyyYE1jURIgcOl8agrfdJ5Def23DIRtiOLRa8jT9cpTLFAuFHN+mrZA/LH9h0gSIg1cPb+0cMASee5uku1KjWcFer7jWA==:
However, the test vectors in the web-bot-auth repo (web_bot_auth_architecture_v1.json) do not include the tag for the signature_agent fields.
Are these the latest test vectors? I see web_bot_auth_architecture_v2.json mentioned in github.com/thibmeu/http-message-signatures-directory but there is no branch with that file
Metadata
Metadata
Assignees
Labels
No labels