Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions draft-ietf-webbotauth-httpsig-protocol.md
Original file line number Diff line number Diff line change
Expand Up @@ -327,7 +327,7 @@ Agents MUST include the following `@signature-params` as defined in {{Section 2.
: as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}}

`expires`
: as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}}
: as defined in {{Section 2.3 of HTTP-MESSAGE-SIGNATURES}}. It is RECOMMENDED that `expires` be no more than 24 hours after `created`.

`keyid`
: MUST be a base64url JWK SHA-256 Thumbprint as defined in {{Section 3.2 of JWK-THUMBPRINT}} for RSA and EC, and in {{Appendix A.3 of JWK-OKP}} for ed25519.
Expand All @@ -339,8 +339,6 @@ The signing key is available to the agent at request time. Algorithms should be

The creation of the signature is defined in {{Section 3.1 of HTTP-MESSAGE-SIGNATURES}}.

It is RECOMMENDED that expiry be no more than 24 hours.

The components above bind the signature to an authority, not to a request. A
signature covering `@authority` alone verifies against any method, path, or body
sent to that authority until it expires, so anyone who observes one request can
Expand Down
Loading