Re: Defining HTTP signature validation (RFC 9421) as a precondition extension to allow 412 as the response code

Justin Richer <jricher@mit.edu> Wed, 26 November 2025 21:53 UTC

Received: by mail2.ietf.org (Postfix) id EB06D9161A44; Wed, 26 Nov 2025 13:53:05 -0800 (PST)
Delivered-To: ietfarch-httpbisa-archive-bis2juki@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E92449161A43 for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Wed, 26 Nov 2025 13:53:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -5.383
X-Spam-Level:
X-Spam-Status: No, score=-5.383 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.017, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org header.b="STqZjwgH"; dkim=pass (2048-bit key) header.d=w3.org header.b="l2XkgIq5"; dkim=pass (1024-bit key) header.d=mit.edu header.b="NfoYBBUs"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l-fVnwxJOeNA for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Wed, 26 Nov 2025 13:53:05 -0800 (PST)
Received: from mab.w3.org (mab.w3.org [IPv6:2600:1f18:7d7a:2700:d091:4b25:8566:8113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 33A849161A3C for <httpbisa-archive-bis2Juki@ietf.org>; Wed, 26 Nov 2025 13:53:05 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:MIME-Version:Content-Type:In-Reply-To:References:Message-ID: Date:CC:To:From:Reply-To; bh=2nB19Fa9rMQxQWojIeHMHo5FJVciG8ZvjzRko3gkfZk=; b= STqZjwgHFbTAsc7smo+EmQ3mkdZcgf0dX69aNhbgTil/su2+ne/lgInkZN55hrgB+Y8osTD0z8LqJ AACy6RP4wyLbklUPMc7HoHn1ry3VPMDZnHkCFy7wIyIm+XyS7K1AtwXaSLtv0DIp/EqHsN3RUPyeB qtrira68t5LggrYYyLtIgdtjiAUU6C1SNsRXTIZoYlz7mKOAUehWofEn7QEt9GwT4KGtSvs36rkP9 K9knhsji08xgdgDyi0e3k9vweueukwyOu6vgt4TpZZX9tb8mTwmc4LJ9V9c2lycKVbCNYxRGJR1C/ txzLjKFrJ6hN+graLAr+cCyhlSitStB5mg==;
Received: from lists by mab.w3.org with local (Exim 4.96) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1vONQb-003b6K-2M for ietf-http-wg-dist@listhub.w3.org; Wed, 26 Nov 2025 21:51:57 +0000
Resent-Date: Wed, 26 Nov 2025 21:51:57 +0000
Resent-Message-Id: <E1vONQb-003b6K-2M@mab.w3.org>
Received: from ip-10-0-0-144.ec2.internal ([10.0.0.144] helo=pan.w3.org) by mab.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <jricher@mit.edu>) id 1vONQZ-003b5V-1J for ietf-http-wg@listhub.w3.internal; Wed, 26 Nov 2025 21:51:55 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=MIME-Version:Content-Type:In-Reply-To:References:Message-ID:Date: Subject:CC:To:From:Reply-To; bh=2nB19Fa9rMQxQWojIeHMHo5FJVciG8ZvjzRko3gkfZk=; t=1764193915; x=1765057915; b=l2XkgIq50ozV+R4mBgHal7wPE198orbbwp+wmbf7ghrnfpj jYFr4XIfyKi4LAmt4il8Lc5MOzrJVVSRVUzNVed8GL0CL+2hTZGisphyKmbnvenS6aTbjPTW+A+j5 ULppKukDaWkqXqd03iZyzGYFNZ/aTmPqNehl/ygQcV4W8+lBBiwp7YiAy4pHQBL62NUt97jTrBkFo T6kMeLCCD000w07MyOYRV7K4xKn4+mt9AghjCeDpobuiSSNUq7T1U2lfblndDuzWW39PaKw1H5tHR LtNGyy4QPOIpz6QBvZ47dRirycvdqF+Gwf0lZGelDdaTjBFTey2uoNthwY9HjTsw==;
Received-SPF: pass (pan.w3.org: domain of mit.edu designates 52.101.46.30 as permitted sender) client-ip=52.101.46.30; envelope-from=jricher@mit.edu; helo=CO1PR03CU002.outbound.protection.outlook.com;
Received: from mail-westus2azon11010030.outbound.protection.outlook.com ([52.101.46.30] helo=CO1PR03CU002.outbound.protection.outlook.com) by pan.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <jricher@mit.edu>) id 1vONQY-002m83-1s for ietf-http-wg@w3.org; Wed, 26 Nov 2025 21:51:55 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Z3L2sanZziutbRDLJ88LyVJapC4D90MrZv7hJAf0saNGdq31KXjUaLzFHNBOCVndbQwJiQK2VVYii8biwVbShgIaHoQRznFgXsVso6snbqj4PM1ISZTmE6M7DLlmHUtniBYh1qmhJa6VHwmugau/foMbMz5aelhBWQDW1qMt+Y80tPquYyEIy0Eaj4AU6aAZ52gQg91nLul5cNgE7zyQfJz8PUN3YFzoFjZp31jogVpNotVez5K1ABT8hk52e/Vq166nXPOpTe8H/UH0vNlUClBuPJs3bY8Qk+kXg+QM2pfuBqZ61aWakqsrQtGfvcDLr5esUPFt0HQd3XtAlp5Lww==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=2nB19Fa9rMQxQWojIeHMHo5FJVciG8ZvjzRko3gkfZk=; b=uPWis//MzA9UhQJIfJengZ27kasd8shQrtlmdGNCr1vO9b8jcdN0wj/2uYNFZ4FbWTz0K4+Dr8MsIwci6Y5mq3BD6i35K00UCwfYIU6v/5ddwjYURV2TTD4eelC2c2kEDe1+/KfHFf5tshfSEWwqf7MlItM/MC58CA6mYZUK9A2OW+ayD+yZ6VFASANyOCj8eccvLGg7i98flrEBp6ifeW22NjD8bJaiCPyn8qe7S5J5lP2Ue0/URyAEhFYfJRWNXhidX31ZCJu+2JTjZ5oJf/P5aXalFyv/1dVLVF1gu8Www6obhFZXE/Me9D2vgigmhNz5JCOLjUtGdmPQ2C3kaQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=mit.edu; dmarc=pass action=none header.from=mit.edu; dkim=pass header.d=mit.edu; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2nB19Fa9rMQxQWojIeHMHo5FJVciG8ZvjzRko3gkfZk=; b=NfoYBBUs49ajv1BTuJV48YxS9wrGHXU38ZP9gMcJwmHERrhgnPhAenL4/8uKAom0JNwjEO/rdyCDjWQ0rS8mrIqiAjnjmY9IaAzJjYLsGXdynWIjxm9SbcliUkwmU4ipjA64mxrd6595F9n1yFmdGFkFSGuaXJ/WoNlghwjrGrU=
Received: from IA0PR01MB8277.prod.exchangelabs.com (2603:10b6:208:48e::13) by SA6PR01MB8702.prod.exchangelabs.com (2603:10b6:806:403::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9366.12; Wed, 26 Nov 2025 21:51:48 +0000
Received: from IA0PR01MB8277.prod.exchangelabs.com ([fe80::7f95:e055:a3eb:82d0]) by IA0PR01MB8277.prod.exchangelabs.com ([fe80::7f95:e055:a3eb:82d0%6]) with mapi id 15.20.9343.016; Wed, 26 Nov 2025 21:51:48 +0000
From: Justin Richer <jricher@mit.edu>
To: DYER Kevin <Kevin.DYER@3ds.com>
CC: "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
Thread-Topic: Defining HTTP signature validation (RFC 9421) as a precondition extension to allow 412 as the response code
Thread-Index: Adxa+3jx3JSoadmJQZWPZhzNfdYywgEI15YA
Date: Wed, 26 Nov 2025 21:51:48 +0000
Message-ID: <5D5A0C3D-8E75-4ADD-89F3-AB5BDB66D718@mit.edu>
References: <d37b2679895f469fabf023f6b5d443d8@3ds.com>
In-Reply-To: <d37b2679895f469fabf023f6b5d443d8@3ds.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=mit.edu;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: IA0PR01MB8277:EE_|SA6PR01MB8702:EE_
x-ms-office365-filtering-correlation-id: 1707a496-7188-439f-2ce3-08de2d360010
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|8096899003|38070700021|7053199007|13003099007;
x-microsoft-antispam-message-info: 0w3o7ro9hXS4cpYRxYsFcUo2AFJN7vNUyjXybtVQPZIbkTFhVaxy30B9GGJbR0KTmnawqCKr9uW8VqqS+evN80Sa/f2MvBZofeF6uT5JZxg93ifonfN9XQ/gV1gJPg2ENHDDENyPFdapCwItiKjYeu3zN+Vz4p7f1faqG+mR3/4YmlNf55gHdVfuJclsuvIKZQ0yUvMsDeVsfj7VFBQnqIBrMY9Ak8Je8MkXLAj6nc1Hy7sCx/Zv+f5AH4mOu684CbanN7zu89NWBPZ/Hi/+cPsXS29WljKwlYwqYtTYrtS+IhPHZhut99DGT1BujpubUaeszRFDL7np47DepY/wRV9vR5NL5KYVqu1fvsnD7jVQVhvKffsfq7wrG6YchWGzA1jgxRD2+o5R6ke4LFEhvLMmQaTkdF1F9qrdHCbcuJGD7OEDQ8HKD11+bbGZgF5HywqACR/CqL1SFyn6X6Kcaj7ne5PiRlApryzzL2HIZun2Z8YZFoPgRj7HWWeOVgVmCWz5TggaDpOthrYz7b2f6UO7QfFlkJxzMQIbNDck4dViqv4xZ2yqml7wKCscXFhhjSYG+vftyqTGne5Bq4e+KQ+5FLnIgP//eLbVLIFZhgavZK4YFEkvXMH1flk22ASPIbsEo5h4UgA+NrFpdf8onZ9ws4TOKkt2pHuKUA7/2trVF58SuX6+qGRq6+wTAMwsdb+TkWtESBtROiXLIZ8OL3eweKegQl+lRYaqBbC2TP7vk1A96fzZ1lyYDUGfaDrI9jI8jqHFPu6jZR6RgP9NJSo52SgYLU349q16WIMjKpcTmDnTkAG9UKSDo5+I2XRh43C0bvXC4MNRZi/FVhwSSih6kYPNU0mgSF5o2QiI2cuLxahKeYihhka95wusRfJ2V1uJs2SH9palfZr2gj+Cd3UgaBRMcC/LGdejYU3FSIXYyOg9LFuap4SnZ2vW7TDly7fNBfJxOX3ggyroJoqfErkiDL0S+FUrvA5/SKKNG/a1Kbqq35Rnl0k9o3jbo9rJqoTebpH1MNceT8WCzlUflbxw1qDGc5nxrTmeApZHeAeOPxAVBTGyvEUL+rTPTRpByKHJbsryzpoSuPPvrSh33jf7QR4ydAVXSCGvjZ5C8T6yDtkiGuH/J17kWHE4DVyNgsJSEEGcoPpcA7aT8Mf878nEIgPgiiq7d2RxS9IB9rRWaPyy0f89mkv+He8RkzI3GM56F+0JhThxaS1syBBu6cK3UwtHurE8gIPZF4z5tstVWPs4IIf43L3QfZr4BDHFDk5qiFZJhe2NNQ/N9J1w9sWiiEuS4CSUPbcUA5qttBRXwYaEslAombSGRNK4QBXK4zt8RpuCXU51dnPT1piM+VvW6pbzjgu3IVwhTotFj/6YTwuT3LDd7ZlKKC8lAwAfizqYEiEkxaZtz9ubvc+EEWHitUi1ZF95SHlocCGebw18kzEUhm6VcSCDps7i1V3x7H3JhixbwT9057WCPIPlyJlIJW6wwo2HdrFC4fJameuIsEL60ovph7HpOgik3Orf3k2E8OX5ftKWGYY3t2Oy0Q==
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:IA0PR01MB8277.prod.exchangelabs.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(8096899003)(38070700021)(7053199007)(13003099007);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EDHM+3UOxvgwPTWoG5aUCvj4ysVO65ghkrk8nh7H2jEoE6gOlMZ9JPRfCsIFQWDglddmisrLDKwgzowQRk0+ViwwNFgka85ORZZuAn9wFVBX7wMO0i0+HbxEdW5Wn73kNmS9B23sH5R4m3WXuihVgd2cOKI4SA6jvK0iYWmDFo20fkygQ1z+Y1MBIFtDAeD1hzYSC5IAEGHMBwT2H0Gz4/O1qsuHv2HrsBtvN6Hw9DVhkLwtM49womoiyZCmb81C6+XmiR+IzawNb4gXyDre1uygdoTWWlijaVJR60h3d/65ttpZJk82/ZKtt1TGAnG4Wc/Aic+G0WdOsARPOUPm+QZJw1t6uT0xZmxotbSIpPmLPa+WXbSFuWo+qg7qQpZsDnfW1EyHyXAwLhzantl+mzuumgPiYWUUTQ10CvS554egXfOd8efYvwG5kGqcVvHH2mf/a0KzRYY95EmlhnA/YhgEYu00Ky+FKO64p2ezMdRQQgOOUs1rttn7cQG8FFMMUSQh6+UklbgRWgU4ZWkCchnyp7lV94Ek0dF4FReJzuW9xvD3VaMkiwt+WHvzSTXuP/0nEGuwQv9hvEOlAvGiNaaxiMb79Xvc6QEiXrPZkq7p7MMvV7leZKcfyeg9KdUTdUDRLfGaksBE5maUeYSgTUTqAc4XvCbdjIEYAc/uFmA2uaI4W2GXB1k0AdBOyhX93cI5yhGxWWx01lUP5iu5AyJ+f8rWTLeDFznzmnyDbBGIdqk4nvcTaE+Tf4WmENt3pu2BBHIdidQGRc45UVo+SDlLYPhL7bPQowiQfWi5mEbUwLtqyYJVVhnr6cbxWa5UCXjs8YSGA2DMiLBrN5uK1mNuWDouHBZXU6sYoMXmsI/lDeS67eATuVlwfF1VzfuVaGxyRTgJwFWRXmp1c01t7rCxPltzlpP5XpRFo1dcCrPx8V6HjUPrlCDZPoMMe5Giw7yNlj6jVO9Zp1enxtZ+vHypYXXgbrH3j+Kt1mMkE8IEZmAg51gMwm9lh/8+8+GkLkVSdXU4MFkNHw3mklc65vaSzqp5YyzNUyxo94m5F9WJUt8f37Fk8oTuvJA9ZZC7nEhcBFNcD69BHdVYAKeKiC4eu9nX1l6FF534UW3MZB4NRZmR3hb4URGdtFu3VJhecizBhg8sJ9uNgkiuo9bdFqGRR31FwjLcV0apxrLBKq2p3i6iE+j5VS6FtkM/KgDleWd2r4muFEl7v7qwJ5a5YECd87p529g4H/YXLVYtdyEsi7um/k03GZb7ti0XdmozRDmwSsTH8+wClH3XAwnLD5DCjfuAgog7gMyt4ApDENK8j/dV8oIfeGJ2X1gA6R7js8FUqCJAylEJ15EwbEMDjzGykLToj1ZefAa6kiJ6+xi57ORxkQQ7+HQpZCIOc8YfTgnFgxomhojH0x09/4TmdO1FJGOd3808VmskAHZxA4f+pUN2xPVDpeDKIEc9PhBwmX34LqoKaMXdV/S4Iz5mYUohEI6QIfkY4FA9S9thr8JdqgDKdaOPMdrjBdsoPLhErAmgQjbO7e264ILoP0Xc8XlnlPIyJyNh2xhVM8nnmXaJNgJHSX6qxRrBO92blmPy
Content-Type: multipart/alternative; boundary="_000_5D5A0C3D8E754ADD89F3AB5BDB66D718mitedu_"
MIME-Version: 1.0
X-OriginatorOrg: mit.edu
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: IA0PR01MB8277.prod.exchangelabs.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1707a496-7188-439f-2ce3-08de2d360010
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Nov 2025 21:51:48.5688 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: s9DrcEr8UGhNtJtm9Sh2SQpyvieP7fLHkdSY+UvhV0D7yWkoPsfHtHYPdbpfKpBr
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA6PR01MB8702
X-W3C-Hub-DKIM-Status: validation passed: (address=jricher@mit.edu domain=mit.edu), signature is good
X-W3C-Hub-Spam-Status: No, score=-3.4
X-W3C-Hub-Spam-Report: ARC_SIGNED=0.001, ARC_VALID=0.001, BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, DMARC_PASS=-0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: pan.w3.org 1vONQY-002m83-1s e735d756099f89ae381eba93a69b5c23
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Defining HTTP signature validation (RFC 9421) as a precondition extension to allow 412 as the response code
Archived-At: <https://www.w3.org/mid/5D5A0C3D-8E75-4ADD-89F3-AB5BDB66D718@mit.edu>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/53576
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

RFC9421 does not specify error codes to be used, as the appropriate error code depends entirely on the part of the overall security stack that the signatures are being used in. If the signature is used as part of an authentication scheme for some other protocol or system, then a 401 would be appropriate for a failure to sign the message appropriately (since the result is that the authentication failed). If you’re doing it as part of precondition checking as your example below, then 412 would be reasonable. It’s entirely up to the application of the signatures to define what errors make sense and how to process them. The details of section 1.4 (https://www.rfc-editor.org/rfc/rfc9421.html#name-application-of-http-message) are about how to apply the signature to an overall system, and the additional kinds of things that you need to define as part of the application. The examples therein are just that, examples, and carry no normative weight. There was some talk in the HTTP-API WG about defining a generic set of error messages per RFC9457, but initial discussions landed on there being many potential error cases that could be returned and the appropriateness of returning those errors specifically for different applications is going to vary.

Ultimately, choose an error code for your application that makes sense for your application.

 — Justin

On Nov 21, 2025, at 10:38 AM, DYER Kevin <Kevin.DYER@3ds.com> wrote:

Hello All,

I am working with a team that is looking to implement HTTP Message signatures and validation within our products. I have not read the entire history of how this specification evolved over time and therefore do not know if this topic was previously discussed. If it was and not acted upon, I apologize up front.

After reviewing the RFC I find the error reporting recommendations for using a status code of 401 is not in-line with [HTTP] RFC 9110 Section 15.5.2 401 Unauthorized. Additionally, the status code 403 does not make sense when requests have been made with credentials being exchanged. The 403 response can be interpreted by intermediary network components, as in ZTNA or identity-aware proxies, as an indicator by the origin/target server to cease all access to this session. If not the network components then the application itself may take action when a 403 is the status response and perform an absolute session termination (SLO).

My interpretation of RFC 9421 has me regarding signature validation as a higher class of preconditions to the HTTP message, much the same as If-Modified-Since, If-Match, etc. But these preconditions are applied before further processing the HTTP message and after any TLS preconditions have been met (SERVER HELLO Certificate Validation, SNI, mTLS, ALPN, etc).  In the Tomcat world this could be implemented at a valve level, to be executed before a single nibble of application code is run.

Prereq:  the server or client has been configured with a valve/filter/servlet/JavaScript function to recognize and operate on all signature components.

If the signature validation is indeed a super class of preconditions that must be validated. And when the signature components are found within the header section of the HTTP message then doesn’t it make sense to use the 412 Precondition Failed as the primary status response from signature validation failure or exception? The 412 response per [HTTP] allows for as much or as little details as necessary in the response body to provide information to the end user.

Best Regards,

Kevin J. Dyer
AMERICAS User Success Engineering Director, Infrastructure and Security
kevin.dyer@3ds.com<mailto:kevin.dyer@3ds.com>

Next OOO –
------------------------------------------------------------------------------------------------------------------------------------
Office:      +1 781 810 3582
Mobile:    +1 978 549 0971

Dassault Systèmes | www.3ds.com<http://www.3ds.com/> | The 3DEXPERIENCE
Dassault Systèmes | 175 Wyman St |Waltham, MA  02451-1223 | United States

This email and any attachments are intended solely for the use of the individual or entity to whom it is addressed and may be confidential and/or privileged.
If you are not one of the named recipients or have received this email in error,
(i) you should not read, disclose, or copy it,
(ii) please notify sender of your receipt by reply email and delete this email and all attachments,
(iii) Dassault Systèmes does not accept or assume any liability or responsibility for any use of or reliance on this email.

Please be informed that your personal data are processed according to our data privacy policy as described on our website. Should you have any questions related to personal data protection, please contact 3DS Data Protection Officer https://www.3ds.com/privacy-policy/contact/