w3c-ccg / http-signatures

Signing HTTP Messages specification
https://w3c-dvcg.github.io/http-signatures/
Other
34 stars 9 forks source link

HTTP signature scheme in the IANA Authentication Scheme Registry #99

Open sebastien-rosset opened 4 years ago

sebastien-rosset commented 4 years ago

Shouldn't "Signature" (or equivalent string) be added as a valid authentication scheme to the IANA Authentication Scheme Registry, which is located at https://www.iana.org/assignments/http-authschemes/http-authschemes.xhtml?

Version 12 of the HTTP-signature draft references RFC 7235 section 4.1, but I don't see any reference to RFC 7235 section 5.1. https://tools.ietf.org/html/rfc7235#section-5.1

Several standard and tools use the value of the authentication scheme, so it would be helpful to have a standardized value for the HTTP scheme. For example, the OpenAPI specification specifies the "scheme" attribute: https://swagger.io/specification/#securitySchemeObject