From 5a71ee1f59551390f6fcba0cee66028ef76f30bf Mon Sep 17 00:00:00 2001 From: Thibault Meunier Date: Mon, 5 Oct 2026 16:58:54 +0200 Subject: [PATCH] [protocol] tie 24h recommendation to expires Closes #133 --- draft-ietf-webbotauth-httpsig-protocol.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/draft-ietf-webbotauth-httpsig-protocol.md b/draft-ietf-webbotauth-httpsig-protocol.md index 37d9f8d..bb558ee 100644 --- a/draft-ietf-webbotauth-httpsig-protocol.md +++ b/draft-ietf-webbotauth-httpsig-protocol.md @@ -327,7 +327,7 @@ Agents MUST include the following `@signature-params` as defined in {{Section 2. : as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}} `expires` -: as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}} +: as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}}. It is RECOMMENDED that `expires` be no more than 24 hours after `created`. `keyid` : MUST be a base64url JWK SHA-256 Thumbprint as defined in {{Section 3.2 of JWK-THUMBPRINT}} for RSA and EC, and in {{Appendix A.3 of JWK-OKP}} for ed25519. @@ -339,8 +339,6 @@ The signing key is available to the agent at request time. Algorithms should be The creation of the signature is defined in {{Section 3.1 of HTTP-MESSAGE-SIGNATURES}}. -It is RECOMMENDED that expiry be no more than 24 hours. - The components above bind the signature to an authority, not to a request. A signature covering `@authority` alone verifies against any method, path, or body sent to that authority until it expires, so anyone who observes one request can