ioggstream / draft-polli-resource-digests-http

THIS REPO WAS MOVED TO https://github.com/httpwg/http-extensions/
https://httpwg.org/http-extensions/draft-ietf-httpbis-digest-headers.html
Other
0 stars 1 forks source link

Using Digest in signatures #20

Closed ioggstream closed 5 years ago

ioggstream commented 5 years ago

I expect

To better detail the usage of Digest in signatures, including:

Questions

Notes

Split from #15

ioggstream commented 5 years ago

For now, we only warn that:

LPardue commented 5 years ago

The challenge here is to add useful guidance that is relevant to Digest and expected usages but without also defining the expected usages completely.

The dependency model is that a signature doesn't need to include a digest but it can, a digest doesn't include a signature. Attempting to explain too much of signature risks inverting the dependency (or at least coupling too tightly).

I think what we have today is sufficient but am open to compelling reasons on what would be really helpful to define in this document.

ioggstream commented 5 years ago

Agree. My point is just avoiding all the problematic usage of Digest in signatures.

Feel free to highlight what is in-scope and what it is not.

ioggstream commented 5 years ago

moved to https://github.com/httpwg/http-extensions/issues/851