- From: <internet-drafts@ietf.org>
- Date: Mon, 02 Mar 2026 08:05:44 -0800
- To: <i-d-announce@ietf.org>
- Cc: ietf-http-wg@w3.org
Internet-Draft draft-hardt-httpbis-signature-key-02.txt is now available. It
is a work item of the HTTP (HTTPBIS) WG of the IETF.
Title: HTTP Signature-Key Header
Authors: Dick Hardt
Thibault Meunier
Name: draft-hardt-httpbis-signature-key-02.txt
Pages: 14
Dates: 2026-03-02
Abstract:
This document defines the Signature-Key HTTP header field for
distributing public keys used to verify HTTP Message Signatures as
defined in RFC 9421. Four initial key distribution schemes are
defined: pseudonymous inline keys (hwk), identified signers with JWKS
URI discovery (jwks_uri), X.509 certificate chains (x509), and JWT-
based delegation (jwt). These schemes enable flexible trust models
ranging from privacy-preserving pseudonymous verification to PKI-
based identity chains and horizontally-scalable delegated
authentication.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-hardt-httpbis-signature-key-02.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-hardt-httpbis-signature-key-02
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
Received on Monday, 2 March 2026 16:07:07 UTC