#rfc9421 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rfc9421, aggregated by home.social.
-
@gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?
-
@gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?
-
@gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?
-
@gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?
-
@gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?
-
@arcaneoverflow @thomasfuchs In the grim future of LLM training data (the year 2037), the Internet is a desolate wasteland. The oceans, the night sky, and all the volcanoes have been boiled away by #slopfondlers fondling their slop. Corporations have wasted quadrillions of dollars and destroyed all code. Programmers have been cast out of society and live online in isolated #fediverse servers. An LLM updated #RFC9421 incorrectly, some servers auto-updated incorrectly, and all communications are down.
Suddenly someone remembers the #y2038 apocalypse! But programming is no longer possible: all LLMs have been #trained_on_trash. Humanity's only chance is to train a new LLM, on non-trash code. But where to find such code? #INTERCAL is the only possible way. Sextillions of dollars are spent training a top-tier LLM model on INTERCAL alone.
It fails. Humanity is gone. -
This is a fairly good summary, @blog @Edent.
You may want to make a note that PHP 8.4 is required to support ed25519 in
ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll needext-sodiumlikesodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey)based on the code in your article.Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.
A bit of pseudo-PHP code here to
foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2... -
This is a fairly good summary, @blog @Edent.
You may want to make a note that PHP 8.4 is required to support ed25519 in
ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll needext-sodiumlikesodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey)based on the code in your article.Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.
A bit of pseudo-PHP code here to
foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2... -
This is a fairly good summary, @blog @Edent.
You may want to make a note that PHP 8.4 is required to support ed25519 in
ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll needext-sodiumlikesodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey)based on the code in your article.Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.
A bit of pseudo-PHP code here to
foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2... -
This is a fairly good summary, @blog @Edent.
You may want to make a note that PHP 8.4 is required to support ed25519 in
ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll needext-sodiumlikesodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey)based on the code in your article.Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.
A bit of pseudo-PHP code here to
foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2... -
This is a fairly good summary, @blog @Edent.
You may want to make a note that PHP 8.4 is required to support ed25519 in
ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll needext-sodiumlikesodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey)based on the code in your article.Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.
A bit of pseudo-PHP code here to
foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2... -
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
-
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
-
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
-
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
-
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
-
@interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).
-
@interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).
-
@interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).
-
@interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).
-
@interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).
-
Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.
It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.
Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.
Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).
#Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12
-
Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.
It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.
Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.
Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).
#Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12
-
Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.
It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.
Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.
Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).
#Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12
-
Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.
It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.
Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.
Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).
#Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12
-
Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.
It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.
Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.
Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).
#Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12
-
The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!
-
The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!
-
The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!
-
The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!
-
The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!
-
When last I left off, I made a pull request to
peertube/http-signaturelibrary try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.So our current ecosystem state is the following:
- PeerTube uses
misskey-dev/node-http-message-signatureslibrary and owns the defacto unmaintainedpeertube/http-signaturelibrary. - Misskey and the rest of the ‘keyverse use
peertube/http-signaturelibrary and Misskey owns the defacto...
- PeerTube uses
-
When last I left off, I made a pull request to
peertube/http-signaturelibrary try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.So our current ecosystem state is the following:
- PeerTube uses
misskey-dev/node-http-message-signatureslibrary and owns the defacto unmaintainedpeertube/http-signaturelibrary. - Misskey and the rest of the ‘keyverse use
peertube/http-signaturelibrary and Misskey owns the defacto...
- PeerTube uses
-
When last I left off, I made a pull request to
peertube/http-signaturelibrary try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.So our current ecosystem state is the following:
- PeerTube uses
misskey-dev/node-http-message-signatureslibrary and owns the defacto unmaintainedpeertube/http-signaturelibrary. - Misskey and the rest of the ‘keyverse use
peertube/http-signaturelibrary and Misskey owns the defacto...
- PeerTube uses
-
When last I left off, I made a pull request to
peertube/http-signaturelibrary try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.So our current ecosystem state is the following:
- PeerTube uses
misskey-dev/node-http-message-signatureslibrary and owns the defacto unmaintainedpeertube/http-signaturelibrary. - Misskey and the rest of the ‘keyverse use
peertube/http-signaturelibrary and Misskey owns the defacto...
- PeerTube uses
-
When last I left off, I made a pull request to
peertube/http-signaturelibrary try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.So our current ecosystem state is the following:
- PeerTube uses
misskey-dev/node-http-message-signatureslibrary and owns the defacto unmaintainedpeertube/http-signaturelibrary. - Misskey and the rest of the ‘keyverse use
peertube/http-signaturelibrary and Misskey owns the defacto...
- PeerTube uses
-
@gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for
@peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the
cavage12Draftexport (and therfc9421export).I think the next step for anyone would be:
- manual...
-
@gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for
@peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the
cavage12Draftexport (and therfc9421export).I think the next step for anyone would be:
- manual...
-
@gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for
@peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the
cavage12Draftexport (and therfc9421export).I think the next step for anyone would be:
- manual...
-
@gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for
@peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the
cavage12Draftexport (and therfc9421export).I think the next step for anyone would be:
- manual...
-
@gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for
@peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the
cavage12Draftexport (and therfc9421export).I think the next step for anyone would be:
- manual...
-
RE: https://mastodon.social/@bagder/116359048796181736
This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).
-
RE: https://mastodon.social/@bagder/116359048796181736
This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).
-
RE: https://mastodon.social/@bagder/116359048796181736
This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).
-
RE: https://mastodon.social/@bagder/116359048796181736
This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).
-
RE: https://mastodon.social/@bagder/116359048796181736
This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).
-
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.
I should probably check again...
-
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.
I should probably check again...
-
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.
I should probably check again...
-
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.
I should probably check again...
-
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.
I should probably check again...
-
RE: https://mastodon.social/@bagder/116359048796181736
Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.
On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
-
RE: https://mastodon.social/@bagder/116359048796181736
Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.
On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
-
RE: https://mastodon.social/@bagder/116359048796181736
Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.
On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?
-
RE: https://mastodon.social/@bagder/116359048796181736
Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.
On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.
Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?