Re: New I-D: HTTP Message Signatures

On Thu, Dec 12, 2019 at 4:22 PM Richard Backman, Annabelle <
richanna@amazon.com> wrote:

> Hello HTTP Working Group,
>
>
>
> I have just published a new I-D on an old topic, HTTP Message Signatures:
> https://datatracker.ietf.org/doc/draft-richanna-http-message-signatures/
>
>
> This document describes a mechanism for creating, encoding, and verifying
> digital signatures or message authentication codes over content within an
> HTTP message. This mechanism supports use cases where the full HTTP message
> may not be known to the signer, and where the message may be transformed
> (e.g., by intermediaries) before reaching the verifier.
>
>
> There is growing widespread interest in this topic (see Justin Richer’s
> SecDispatch presentation at IETF 106); the goal of this draft is to provide
> a general purpose signing mechanism that can be used directly or profiled
> to fit specific use cases.
>

Hi,

Thanks for writing this up. I'd like Appendix B to compare and contrast the
draft with AWSv4, which seems to be good enough for many use cases.

In particular, I've noticed that mobile clients tend to segment uploads so
they can be resumed, and servers segment streaming media so they can switch
quality settings using things like HLS and DASH.

thanks,
Rob

Received on Sunday, 15 December 2019 21:12:25 UTC