Skip to content
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

fedi wiki

  1. Home
  2. Technical Discussion
  3. Tracking RFC 9421 Adoption

Tracking RFC 9421 Adoption

Scheduled Pinned Locked Moved Technical Discussion
2 Posts 2 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E This user is from outside of this forum
    E This user is from outside of this forum
    evan@activitypub.space
    wrote last edited by evan@activitypub.space
    #1

    One of the big pain points for ActivityPub developers is supporting HTTP Signature in their servers. The Fediverse uses an out-dated draft standard, draft cavage 12. There's a helpful ActivityPub and HTTP Signatures report from the SocialCG, but it's still kind of a slog.

    Some server software has begun the pivot to using double-knocking, capability discovery, or something else.

    To track support for RFC 9421, I added an adoption matrix to the ActivityPub HTTP Signature repo. I grabbed all the software listed on FediDB, and laid out a matrix of whether it accepts RFC 9421 signatures for GET and POST or sends RFC 9421 for GET and POST. I also included a way to find relevant bug-tracker issues.

    https://swicg.github.io/activitypub-http-signature/RFC9421

    It would be a huge help to get some more eyes and data on this adoption matrix. If you know about a Fediverse server package's support for RFC 9421, including your own, please make a PR against the RFC9421.md file in the swicg/activitypub-http-signature repo.

    Thanks!

    1 Reply Last reply
    3
    • julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.space
      wrote last edited by
      #2

      I will say that adoption of RFC 9421 is a more difficult than anticipated because many of us hacked our cavage-12 implementations in by testing against Mastodon.

      Specifically, I remember a very old (and outdated even then!) blog post by @gargron@mastodon.social about how Signatures were implemented by Mastodon, and that formed the basis of how NodeBB signed its messages.

      I'm glad we're moving on but I think for the majority of us, having a reliable library to do the heavy lifting is important.

      Don't roll your own HTTP signatures folks!

      1 Reply Last reply
      1

      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

      With your input, this post could be even better 💗

      Register Login
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post