Re: Signing Set-Cookie

> This would also apply to treating MAC as a Signature wouldn't it?


That is also hard to stomach, though for a different reason and it falls short of being absolutely unacceptable.  Just.  We accept TLS PSK modes on the understanding that there are just two entities and they each know their roles (the latter part thanks to Selfie).  The same *could* apply to a "symmetric signature" scheme here.  It's a giant footgun, but this spec is a collection of footguns of varying size already, so I don't get too excited about there being one more.

