home.social

#rfc9421 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rfc9421, aggregated by home.social.

fetched live
  1. @gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?

    swicg.github.io/activitypub-ht

  2. @gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?

    swicg.github.io/activitypub-ht

  3. @gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?

    swicg.github.io/activitypub-ht

  4. @gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?

    swicg.github.io/activitypub-ht

  5. @gabboman Hey, friend. We've got some question marks about you in the #ActivityPub coverage matrix for #RFC9421. Does #wafrn accept RFC 9421 signatures? Does it send them (harder)?

    swicg.github.io/activitypub-ht

  6. @arcaneoverflow @thomasfuchs In the grim future of LLM training data (the year 2037), the Internet is a desolate wasteland. The oceans, the night sky, and all the volcanoes have been boiled away by #slopfondlers fondling their slop. Corporations have wasted quadrillions of dollars and destroyed all code. Programmers have been cast out of society and live online in isolated #fediverse servers. An LLM updated #RFC9421 incorrectly, some servers auto-updated incorrectly, and all communications are down.
    Suddenly someone remembers the #y2038 apocalypse! But programming is no longer possible: all LLMs have been #trained_on_trash. Humanity's only chance is to train a new LLM, on non-trash code. But where to find such code? #INTERCAL is the only possible way. Sextillions of dollars are spent training a top-tier LLM model on INTERCAL alone.
    It fails. Humanity is gone.

  7. This is a fairly good summary, @blog @Edent.

    You may want to make a note that PHP 8.4 is required to support ed25519 in ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll need ext-sodium like sodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey) based on the code in your article.

    Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.

    A bit of pseudo-PHP code here to 

        foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2...

  8. This is a fairly good summary, @blog @Edent.

    You may want to make a note that PHP 8.4 is required to support ed25519 in ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll need ext-sodium like sodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey) based on the code in your article.

    Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.

    A bit of pseudo-PHP code here to 

        foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2...

  9. This is a fairly good summary, @blog @Edent.

    You may want to make a note that PHP 8.4 is required to support ed25519 in ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll need ext-sodium like sodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey) based on the code in your article.

    Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.

    A bit of pseudo-PHP code here to 

        foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2...

  10. This is a fairly good summary, @blog @Edent.

    You may want to make a note that PHP 8.4 is required to support ed25519 in ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll need ext-sodium like sodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey) based on the code in your article.

    Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.

    A bit of pseudo-PHP code here to 

        foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2...

  11. This is a fairly good summary, @blog @Edent.

    You may want to make a note that PHP 8.4 is required to support ed25519 in ext-openssl, which hopefully most people will be on, but maybe not. Otherwise you’ll need ext-sodium like sodium_crypto_sign_verify_detached(base64_decode($signatureB64), $signatureBase, $publicKey) based on the code in your article.

    Also I think it would be helpful to explain the various signature components from the rest of the signature parameters.

    A bit of pseudo-PHP code here to 

        foreach ($componentNames as $name) {$components[$name] = match ($name) {// 2...

  12. I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.

    Feedback welcome - especially those explaining politely why I'm a wrong about this.

    github.com/mastodon/mastodon/i

  13. I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.

    Feedback welcome - especially those explaining politely why I'm a wrong about this.

    github.com/mastodon/mastodon/i

  14. I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.

    Feedback welcome - especially those explaining politely why I'm a wrong about this.

    github.com/mastodon/mastodon/i

  15. I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.

    Feedback welcome - especially those explaining politely why I'm a wrong about this.

    github.com/mastodon/mastodon/i

  16. I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.

    Feedback welcome - especially those explaining politely why I'm a wrong about this.

    github.com/mastodon/mastodon/i

  17. @interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).

  18. @interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).

  19. @interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).

  20. @interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).

  21. @interledger @evan If anyone would like this bounty, then you can fork @peertube/http-signature into its own NPM namespace using my forked branch, which provides a backward-compatible RFC 9421 implementation that would make it easier for software to handle both cavage-12 draft and RFC 9421. You will probably need to maintain it for a couple of years so that the JavaScript/TypeScript ActivityPub community can coalesce and focus on a stable replacement (probably fedify or misskey).

  22. @[email protected]

    Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.

    It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.

    Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.

    Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).

    #Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12

  23. @[email protected]

    Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.

    It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.

    Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.

    Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).

    #Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12

  24. @[email protected]

    Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.

    It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.

    Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.

    Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).

    #Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12

  25. @[email protected]

    Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.

    It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.

    Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.

    Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).

    #Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12

  26. @[email protected]

    Double-Knock... i can just guess, that some considering RFC 9421 signatures as the preferred variant, so that this is suggested to try first.

    It might be possible, that i start to do a double-knocking at the beginning with Draft Cavage 12 first.

    Regarding "to send both signatures at once": Both signature types are using a "Signature" header. So it doesn't look like you can send both signature types at once.

    Btw.: Was your post shortened on #Mastodon? (I saw it first on norden.social).

    #Fediverse #ActivityPub #Signature #HTTP #RFC9421 #DraftCavage12

  27. The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!

    interledger.org/grant/open-pay

  28. The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!

    interledger.org/grant/open-pay

  29. The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!

    interledger.org/grant/open-pay

  30. The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!

    interledger.org/grant/open-pay

  31. The Interledger Foundation @Interledger has an open funding call for libraries implementing #RFC9421 (HTTP Signature). This is crucial infrastructure for #ActivityPub. Go get that money!

    interledger.org/grant/open-pay

  32. When last I left off, I made a pull request to peertube/http-signature library try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.

    So our current ecosystem state is the following:

    • PeerTube uses misskey-dev/node-http-message-signatures library and owns the defacto unmaintained peertube/http-signature library.
    • Misskey and the rest of the ‘keyverse use peertube/http-signature library and Misskey owns the defacto...

  33. When last I left off, I made a pull request to peertube/http-signature library try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.

    So our current ecosystem state is the following:

    • PeerTube uses misskey-dev/node-http-message-signatures library and owns the defacto unmaintained peertube/http-signature library.
    • Misskey and the rest of the ‘keyverse use peertube/http-signature library and Misskey owns the defacto...

  34. When last I left off, I made a pull request to peertube/http-signature library try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.

    So our current ecosystem state is the following:

    • PeerTube uses misskey-dev/node-http-message-signatures library and owns the defacto unmaintained peertube/http-signature library.
    • Misskey and the rest of the ‘keyverse use peertube/http-signature library and Misskey owns the defacto...

  35. When last I left off, I made a pull request to peertube/http-signature library try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.

    So our current ecosystem state is the following:

    • PeerTube uses misskey-dev/node-http-message-signatures library and owns the defacto unmaintained peertube/http-signature library.
    • Misskey and the rest of the ‘keyverse use peertube/http-signature library and Misskey owns the defacto...

  36. When last I left off, I made a pull request to peertube/http-signature library try to help the JavaScript ecosystem reach RFC 9421 parity while being backwards-compatible with cavage-12 draft implementations. There has not been any traction on this yet. Maybe because PeerTube has abandoned its own use of the library.

    So our current ecosystem state is the following:

    • PeerTube uses misskey-dev/node-http-message-signatures library and owns the defacto unmaintained peertube/http-signature library.
    • Misskey and the rest of the ‘keyverse use peertube/http-signature library and Misskey owns the defacto...

  37. @gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for @peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.

    The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the cavage12Draft export (and the rfc9421 export).

    I think the next step for anyone would be:

    • manual...

  38. @gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for @peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.

    The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the cavage12Draft export (and the rfc9421 export).

    I think the next step for anyone would be:

    • manual...

  39. @gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for @peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.

    The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the cavage12Draft export (and the rfc9421 export).

    I think the next step for anyone would be:

    • manual...

  40. @gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for @peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.

    The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the cavage12Draft export (and the rfc9421 export).

    I think the next step for anyone would be:

    • manual...

  41. @gabboman I decided to hack on this the past few nights, and came up with an experimental, backwards-compatible implementation that I created a draft pull request for @peertube/http-signature. I tried to follow the library’s coding style of the original as much as possible.

    The idea of backwards-compatibility is that you can drop this into an existing application and nothing will break. There are deprecation messages that may surface in logs to guide changing from using the function exports to the cavage12Draft export (and the rfc9421 export).

    I think the next step for anyone would be:

    • manual...

  42. RE: mastodon.social/@bagder/116359

    This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).

    #RFC9421 #RFC9635 #GNAP #OpenPayments #API

  43. RE: mastodon.social/@bagder/116359

    This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).

    #RFC9421 #RFC9635 #GNAP #OpenPayments #API

  44. RE: mastodon.social/@bagder/116359

    This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).

    #RFC9421 #RFC9635 #GNAP #OpenPayments #API

  45. RE: mastodon.social/@bagder/116359

    This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).

    #RFC9421 #RFC9635 #GNAP #OpenPayments #API

  46. RE: mastodon.social/@bagder/116359

    This feature, once acceptable for merging, will make it easier to use curl with OpenPayments.dev and other APIs using GNAP (RFC 9635 Grant Negotiation and Authorization Protocol, the successor to OAuth 2).

    #RFC9421 #RFC9635 #GNAP #OpenPayments #API

  47. Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

    I should probably check again...

  48. Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

    I should probably check again...

  49. Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

    I should probably check again...

  50. Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

    I should probably check again...

  51. Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    The last time I checked, Lemmy, GoToSocial, Friendica, and the ‘keys to name a few did not handle it. Mastodon didn’t if you included requiring ed25519. But I haven’t checked the code bases or my logs in a month or two, @julian. At that time there wasn’t much progress on peertube/http-signatures or superseriousbusiness/httpsig.

    I should probably check again...

  52. RE: mastodon.social/@bagder/116359

    Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

    On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

    Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    #ActivityPub #FediDev #RFC9421

  53. RE: mastodon.social/@bagder/116359

    Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

    On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

    Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    #ActivityPub #FediDev #RFC9421

  54. RE: mastodon.social/@bagder/116359

    Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

    On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

    Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    #ActivityPub #FediDev #RFC9421

  55. RE: mastodon.social/@bagder/116359

    Could be potentially nice for fediverse server testing, as more implementations make the jump to final RFC 9421 HTTP signatures.

    On the flip side, ever more complex curl invocations (here: Accept header plus signature fields plus key file, presumably) suggest use of more specialized CLI tools, such as provided by @fedify, or at least scripts/aliases.

    Speaking of RFC 9421, which notable fediverse implementations can't handle it yet? Anyone keeping track?

    #ActivityPub #FediDev #RFC9421