<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Tracking RFC 9421 Adoption]]></title><description><![CDATA[<p dir="auto">One of the big pain points for ActivityPub developers is supporting HTTP Signature in their servers. The Fediverse uses an out-dated draft standard, <a href="https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12" rel="nofollow ugc">draft cavage 12</a>. There's a helpful <a href="https://swicg.github.io/activitypub-http-signature/" rel="nofollow ugc">ActivityPub and HTTP Signatures</a> report from the SocialCG, but it's still kind of a slog.</p>
<p dir="auto">Some server software has begun the pivot to using <a href="https://swicg.github.io/activitypub-http-signature/#how-to-upgrade-supported-versions" rel="nofollow ugc">double-knocking</a>, <a href="https://codeberg.org/fediverse/fep/src/branch/main/fep/844e/fep-844e.md" rel="nofollow ugc">capability discovery</a>, or something else.</p>
<p dir="auto">To track support for RFC 9421, I added an <a href="https://swicg.github.io/activitypub-http-signature/RFC9421" rel="nofollow ugc">adoption matrix</a> to the ActivityPub HTTP Signature repo. I grabbed all the <a href="https://fedidb.com/software/" rel="nofollow ugc">software listed on FediDB</a>, and laid out a matrix of whether it accepts RFC 9421 signatures for GET and POST or sends RFC 9421 for GET and POST. I also included a way to find relevant bug-tracker issues.</p>
<p dir="auto"><a href="https://swicg.github.io/activitypub-http-signature/RFC9421" rel="nofollow ugc">https://swicg.github.io/activitypub-http-signature/RFC9421</a></p>
<p dir="auto">It would be a huge help to get some more eyes and data on this adoption matrix. If you know about a Fediverse server package's support for RFC 9421, including your own, please make a PR against the <a href="http://RFC9421.md" rel="nofollow ugc">RFC9421.md</a> file in the <a href="https://github.com/swicg/activitypub-http-signature" rel="nofollow ugc">swicg/activitypub-http-signature</a> repo.</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://fedi.wiki/topic/ca39aa21-c7a2-4345-a2e5-d5d510ee64cd/tracking-rfc-9421-adoption</link><generator>RSS for Node</generator><lastBuildDate>Tue, 25 Aug 2026 08:06:56 GMT</lastBuildDate><atom:link href="https://fedi.wiki/topic/ca39aa21-c7a2-4345-a2e5-d5d510ee64cd.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 16 Aug 2026 18:11:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Tracking RFC 9421 Adoption on Mon, 17 Aug 2026 17:18:00 GMT]]></title><description><![CDATA[<p dir="auto">I will say that adoption of RFC 9421 is a more difficult than anticipated because many of us hacked our cavage-12 implementations in by testing against Mastodon.</p>
<p dir="auto">Specifically, I remember a very old (and outdated even then!) blog post by <a href="https://activitypub.space/user/gargron%40mastodon.social" rel="nofollow ugc">@gargron@mastodon.social</a> about how Signatures were implemented by Mastodon, and that formed the basis of how NodeBB signed its messages.</p>
<p dir="auto">I'm glad we're moving on but I think for the majority of us, having a reliable library to do the heavy lifting is important.</p>
<p dir="auto">Don't roll your own HTTP signatures folks!</p>
]]></description><link>https://fedi.wiki/post/https://activitypub.space/post/2367</link><guid isPermaLink="true">https://fedi.wiki/post/https://activitypub.space/post/2367</guid><dc:creator><![CDATA[julian@activitypub.space]]></dc:creator><pubDate>Mon, 17 Aug 2026 17:18:00 GMT</pubDate></item></channel></rss>