Re: Call for adoption: draft-hardt-httpbis-signature-key-08 (Ends 2026-09-07)

Dick Hardt <dick.hardt@gmail.com> Mon, 17 August 2026 19:49 UTC

Received: by mail2.ietf.org (Postfix) id 1747312B3FBD8; Mon, 17 Aug 2026 12:49:59 -0700 (PDT)
Delivered-To: ietfarch-httpbisa-archive-bis2juki@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 139D112B3FBD7 for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Mon, 17 Aug 2026 12:49:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786996199; bh=q8PlworeAa2f+yA40CtPEIHZibU4nxIOyvMyQXZ3g1s=; h=Resent-Date:References:In-Reply-To:Reply-To:From:Date:To:Cc: Subject:Resent-From:Resent-Sender:List-Id:List-Help:List-Post: List-Unsubscribe; b=L9gYu0I12OaN/cdjEKSxg/Ye5dNh53JQKjRPlj0KCGWm155D5uNNtNnSyKu9D7Kow 7aTcbVnlFC9rs/FHZDeeZkrpUWtjSERFbdIvvA6mzql8CYnmbZitgWappB0p1z5yDK qvtCN7kyM3mDtHtLpWri9+3gH6n/wUSehshMRFjA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -5.399
X-Spam-Level:
X-Spam-Status: No, score=-5.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=w3.org header.b="Cg91z4jp"; dkim=pass (2048-bit key) header.d=w3.org header.b="Mw4s3L7e"; dkim=pass (2048-bit key) header.d=gmail.com header.b="C7voLHMS"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i19PEwJGlIzD for <ietfarch-httpbisa-archive-bis2Juki@mail2.ietf.org>; Mon, 17 Aug 2026 12:49:58 -0700 (PDT)
Received: from mab.w3.org (mab.w3.org [IPv6:2600:1f18:7d7a:2700:d091:4b25:8566:8113]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5069712B3FBCC for <httpbisa-archive-bis2Juki@ietf.org>; Mon, 17 Aug 2026 12:49:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Subject:Content-Type:Cc:To:Message-ID:Date:From:Reply-To:In-Reply-To: References:MIME-Version; bh=Ji4RXe9rMeqA8Cla7YI8cEfKZYtI75lpan3ZSfFFT8c=; b=C g91z4jpI51Y7QmUCTLdd16KWoDqeYYd6TFaHMvgowdWEcvnj9oHHmsbQcSLY52NkNswzwcWGbeA7A /EwI08Qb37uXQa+uksIJ0kwfE33MMFIiDlL21Mn5cXpof3BIejzA++YWuCxh44Qi5qSG8Dw9UjH6k lfH/Vo8cnF75/AWz1UAHrg20DoufnO5nlv/x2btaTqFLSoxsGeSt3rXH8ORXFbRL4sT9d+8jPHndw PiALyOggEK7gq7vjxhQDUyd9xLIGVe6vLLyA74umZyOCPSdNupgzZQ5U3qvi73X1f8cLbtkcPNo8l d8seMQ/q0qu3Nu5iF0vW06RTKr3DBYrhw==;
Received: from lists by mab.w3.org with local (Exim 4.98.2) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1ww3KV-00000009qOe-3DxV for ietf-http-wg-dist@listhub.w3.org; Mon, 17 Aug 2026 19:49:07 +0000
Resent-Date: Mon, 17 Aug 2026 19:49:07 +0000
Resent-Message-Id: <E1ww3KV-00000009qOe-3DxV@mab.w3.org>
Received: from ip-10-0-0-144.ec2.internal ([10.0.0.144] helo=pan.w3.org) by mab.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from <dick.hardt@gmail.com>) id 1ww3KT-00000009qNj-1QUx for ietf-http-wg@listhub.w3.internal; Mon, 17 Aug 2026 19:49:05 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=w3.org; s=s1; h=Content-Type:Cc:To:Subject:Message-ID:Date:From:Reply-To:In-Reply-To: References:MIME-Version; bh=Ji4RXe9rMeqA8Cla7YI8cEfKZYtI75lpan3ZSfFFT8c=; t=1786996145; x=1787860145; b=Mw4s3L7eI+hw9UwOf70+fNx5Je9IwA7n5CLj9wA9KhJd69F fw0JDYvNvq/mcU6qCxjEQ59fuKgn6ND/j0Jet2w9qisOMi6tcUiI9MmfZcZM4ZEBC2Ow7kXwvV7Qp FF5TrXac972pjRXIM2HBiKY6TT3mPl15Rqwajk82dK+Xm9mNjRujW6qaQE/wURLJN5bRCE7CDgsr4 9H+Ab2PjLLcXpFa8FUaIBpcKCcNV9QEzCMhBbasljn1uLGkjT4vwcAeZoTb4KR/H3se6vMG0O+PRb fY7uV1x2v7pPnVD2/ZwdAKli/6zeRBASxgrlQs0YJRZTDNP+d7LQAcuiFqrmsF3Q==;
Received-SPF: pass (pan.w3.org: domain of gmail.com designates 2607:f8b0:4864:20::333 as permitted sender) client-ip=2607:f8b0:4864:20::333; envelope-from=dick.hardt@gmail.com; helo=mail-ot1-x333.google.com;
Received: from mail-ot1-x333.google.com ([2607:f8b0:4864:20::333]) by pan.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from <dick.hardt@gmail.com>) id 1ww3KS-0000000AEUy-2UXp for ietf-http-wg@w3.org; Mon, 17 Aug 2026 19:49:05 +0000
Received: by mail-ot1-x333.google.com with SMTP id 46e09a7af769-7ec3b429a3aso2543808a34.1 for <ietf-http-wg@w3.org>; Mon, 17 Aug 2026 12:49:04 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786996141; cv=none; d=google.com; s=arc-20260327; b=o+FTrslknvsNvuf+/ndAtV5oDqbPZOcI4D97LTuQqX5RzT31/NNAi5X9QZuZEE7sAR lo4daA+LAG7tmBiLqOqW/DlfnSEFrhjfqRh7JXYd3fGVBwvKvhEFdsoNc7qjI9gkaIk/ ZyY/tv5a1tNLY6+ZFvRkngeshT7USA7xbRiP1xM4GRLdUi8tVpQsFY9eY/TsL3XaTszZ pmK0LBgIxindw70euk4hoIRTIEMA11/SeqRiQo9Uz9r6EQuuQZ0m5OITi3BXMJwYByQi 7p8jL4H+oTZRIEwy0SbOPfPOE5prGzkx3m1dGOUxH3wi3/LG/MITPuAKkMwRJTrZnGpB h6jA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:reply-to:in-reply-to:references :mime-version:dkim-signature; bh=Ji4RXe9rMeqA8Cla7YI8cEfKZYtI75lpan3ZSfFFT8c=; fh=Z+cNtHeQ2egAZSLQozff8uGWmdECtonboXBxosMKGBo=; b=jsDhPULMCRJWz59Lofq7zBrBnK3y738vVsDan3nvEJSqk0T4LioGQq6gYRJ6xWSSen gJft3hkwTqz9Zo4y1JwNEcUncKHmHfkdThSeh7owRMqDvrHpEmsITvCi0z3+B1KRc3fQ ZH200qkSnq73V+zUt7KRWKRugWI6Xh7yZHOELrV/aED64JOGDb0GllBtHOSNRqDf6YPo eSf9qGN2c57sLZ1jfVtrvuWnXeDanbh/ZaL7Gkwo/hIgdMTgcOsZPjnSZOhJMnV5i1zu 5GygzWZPQBW6RYrIb6sjfbOPXAKip9y3zn3X0FyIqxFqGCOnp3eFoAtE27eVcF8nptQW yAPQ==; darn=w3.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786996141; x=1787600941; darn=w3.org; h=content-type:cc:to:subject:message-id:date:from:reply-to :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ji4RXe9rMeqA8Cla7YI8cEfKZYtI75lpan3ZSfFFT8c=; b=C7voLHMSuXQYaAYm3ZxPUPiSms8M7IBVg0nY4YYZr1X2MYQ0g4ciGCgXl1ZJyITBew yJ0uJCLaITPIDIItmz8tS63RKVj0QbGUO4D1HkHvuCXS/jEQ8vKHUw6Fo5haX7BvSUSw kR9wh/QJ95V/jRiOOvExHlgFs+TNaK0PIUp+1dvYoR0M3mD1AAAeb+xmtt5Jj/Bu3Ru3 lmJo4BijN69qi3qvZusC7htKd8IQ4gjo2xwp0SkG6nk42FoCix22o6KyFsw4CBYMzqRH JdOKnBE0hCLdyhy9trflTlmSykRBmJ8MMSwvWxzUouVWpMljCyz7EWIpkb79RP6ga1b+ CJjg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786996141; x=1787600941; h=content-type:cc:to:subject:message-id:date:from:reply-to :in-reply-to:references:mime-version:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Ji4RXe9rMeqA8Cla7YI8cEfKZYtI75lpan3ZSfFFT8c=; b=tWrrwPy5DnZ5gTRiNvBma7uti6dHFEx2qgMQk/nwFScw+if5bl+QRs7UJ4/iQqk8my WikmpAODTFRSx9FZLlDc7vWgSmGq78p2heB1dmy+39OGBBz7AMTCEgQXZvSJ7QVxjkUx 8CwqxnB5pf9sQiXxk6qtBii90Lc6LL/A8GUxCE3S6m46w2TjyId89WAKqXJliKhlFRYd jIL5m2yDz2K+bl27AtSIYTwblxVfjYxr6VAg3stqcebZo/F0sQ+5+4rHxP1EeBc5yGhJ SgzBOAhHvOciVV08pYq+Hl7fgHhgpEupfLk5Bxdqdq5Qdq+zKItyo+Erkk1Thl5orAh6 zDKw==
X-Forwarded-Encrypted: i=1; AHgh+RrBDvJzDupE7cEdkBut84vHyh66hunBRedZqAWHymPMZKDPob3IYaCvsD0kl6e7v/DUW3+d1a1FBQ3gQ+s=@w3.org
X-Gm-Message-State: AOJu0YzlWHya21/0VOgxYZiLn/2LEcmfnWw9MQwQ6ysEId/32VfyUmxN K/ZzdzmvfGzLpAcr2C91Fsa2EDmBpiV2XUTqiB0VORmVBbPELFePHZAqL6YllU84nQ+1wk2R1ub gvc3gP0Ldftg+xrk3IOoZieAVwjs6TRE=
X-Gm-Gg: AR+sD10njxJsFNjeSrKgiIcQgpuIm3UaYiPHriPVfUetjr3Cc6VEfa9nxwvP6sR8d+A RiiI3tRyxpzGFy62oG/LxgIvLwvacea7Ripe3f2g6bI161JVoYPtlzsNFQ5fxLnkL6Mzf9ao+Q1 PDoYTy85Nx9cD6d/mRqX2wj2wrHukhdevQrI0m7CPnytq9vzEkr2wVbp+qU1Y/6bKsd+1PZevo2 IiHhJnlyKpdMBINlosjQ9SRmUd3KtuIFV25ZNLdjAX/ls6HQXaH0LHDAT4jqAFW5CNH3OVmzwE9 VyIJFZBdfNw5ljYM0ToIxM8v3oQ7hvVyeTfbvHoy27L1f0PY8P9uzcGrpS0g481i88XN4OgD91I =
X-Received: by 2002:a05:6830:6687:b0:7e6:e1d2:3bd0 with SMTP id 46e09a7af769-7f423e93218mr3368112a34.10.1786996140893; Mon, 17 Aug 2026 12:49:00 -0700 (PDT)
MIME-Version: 1.0
References: <178693884262.433177.17551183654925667153@dt-datatracker-7c6ddbc678-86d5j> <C04B5758-4DFA-40A4-B5C1-9740EB0BE47D@mit.edu> <CA+9kkMC4tBPYz_eQDTmrmUj1fCHbKfLAgpUCBF2nREU9aJ_t7w@mail.gmail.com>
In-Reply-To: <CA+9kkMC4tBPYz_eQDTmrmUj1fCHbKfLAgpUCBF2nREU9aJ_t7w@mail.gmail.com>
Reply-To: Dick.Hardt@gmail.com
From: Dick Hardt <dick.hardt@gmail.com>
Date: Mon, 17 Aug 2026 20:48:24 +0100
X-Gm-Features: AcwNN1Uup71MljakrpZ46yol3AbAa6vvG_HGYIFDvDeyChs_e2uCHGEQxM5PRhA
Message-ID: <CAD9ie-tOzVA3=ErxC1hSU=_wpbqyTAqw6mAuKJZnBruAOU2CUg@mail.gmail.com>
To: Ted Hardie <ted.ietf@gmail.com>, Martin Thomson <mt@lowentropy.net>
Cc: Justin Richer <jricher@mit.edu>, Tommy Pauly <tpauly.ietf@gmail.com>, "draft-hardt-httpbis-signature-key@ietf.org" <draft-hardt-httpbis-signature-key@ietf.org>, "httpbis-chairs@ietf.org" <httpbis-chairs@ietf.org>, "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
Content-Type: multipart/alternative; boundary="0000000000003168d206594376db"
X-W3C-Hub-DKIM-Status: validation passed: (address=dick.hardt@gmail.com domain=gmail.com), signature is good
X-W3C-Hub-Spam-Status: No, score=-6.1
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, DMARC_PASS=-0.001, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: pan.w3.org 1ww3KS-0000000AEUy-2UXp 205b30ca7906ec922866934ce3faf910
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for adoption: draft-hardt-httpbis-signature-key-08 (Ends 2026-09-07)
Archived-At: <https://www.w3.org/mid/CAD9ie-tOzVA3=ErxC1hSU=_wpbqyTAqw6mAuKJZnBruAOU2CUg@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/54112
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Hi Ted

No disagreement from us. If the consensus of the working group after
adoption and discussion is one header per scheme, the authors would take
that approach. That is why we are proposing adoption — to tap the working
group's judgment on exactly this kind of question.

We are okay making breaking changes. Despite a fair number of
implementations, -08 raised RFC 9864's RECOMMENDED to a requirement: every
conveyed JWK MUST carry a fully-specified alg, and the polymorphic EdDSA
identifier MUST NOT be used. The implementation count is not what is
holding the design in place.

We are not deferring the one header per scheme though for lack of a
position, though. Martin and I discussed this 1:1 in Vienna, where he
pointed me at RFC 9170. Thibault and I worked through his feedback and
concluded that the benefits of a single header outweighed a header per
scheme. We documented that in Appendix A.5, "Why a Scheme Token Instead of
a Header per Scheme?":

https://dickhardt.github.io/signature-key/draft-hardt-httpbis-signature-key.html#name-why-a-scheme-token-instead-

RFC 9170 also drove the third invariant in Section 2 — unknown schemes and
algorithms get defined, mandatory feedback, so the extension point is
exercised on ordinary traffic rather than only when a new value is first
deployed. The other half of Martin's February message asked for use cases
motivating the formats; each scheme in Section 3 now carries its own.

Martin: given that additional context, we would value your feedback.

/Dick



On Mon, Aug 17, 2026 at 6:07 PM Ted Hardie <ted.ietf@gmail.com> wrote:

> Hi Justin,
>
> Martin's point that doing this in multiple headers rather than a single
> header could be correct, but it strikes me as the sort of decision the
> working group could take once change control shifts.  If the authors
> disagree with that take, though, now would be the right time to say so.
>
> regards,
>
> Ted
>
> On Mon, Aug 17, 2026 at 5:43 PM Justin Richer <jricher@mit.edu> wrote:
>
>> I do not support adoption of this document. It adds layers of
>> complication to key negotiation that are almost certain to lead to
>> interoperability problems and security holes. Fundamentally, it conflates
>> pass-by-value, pass-by-reference, and lookup semantics into a single
>> multi-format structure. This alone is, to me, sufficient cause for concern
>> to reject it outright.
>>
>> In spite of the updates to the text, I still agree with Martin’s concerns
>> from earlier this year:
>> https://lists.w3.org/Archives/Public/ietf-http-wg/2026JanMar/0067.html
>>
>> If anything, the new text makes the problem worse, not better.
>>
>> Furthermore, the draft creates a higher-level negotiation protocol and
>> confuses the process with the addition of several new headers in addition
>> to Accept-Signature, which already covers to the existing parameters.
>>
>>  — Justin
>>
>> On Aug 16, 2026, at 11:54 PM, Tommy Pauly via Datatracker <
>> noreply@ietf.org> wrote:
>>
>> This message starts a httpbis WG Call for Adoption of:
>> draft-hardt-httpbis-signature-key-08
>>
>> This Working Group Call for Adoption ends on 2026-09-07
>>
>> Abstract:
>>   This document defines five HTTP header fields for use with HTTP
>>   Message Signatures as defined in RFC 9421.  The Signature-Key request
>>   header distributes public keys used to verify signatures, with eight
>>   initial key distribution schemes: pseudonymous inline keys (hwk),
>>   self-issued key delegation via JWK Thumbprint JWTs (jkt-jwt),
>>   identified signers with JWKS URI discovery (jwks_uri), direct JWKS
>>   fetch (jwks), JWT-based delegation (jwt), self-issued JWTs (self-
>>   jwt), X.509 certificate chains (x509), and references to previously
>>   cached assertions (cached).  The Accept-Signature-Scheme and Accept-
>>   Signature-Alg response headers state the schemes and algorithms a
>>   server accepts, so a client can select both before it signs.  The
>>   Signature-Error response header provides structured error information
>>   when signature verification fails, and the Signature-Key-Cache
>>   response header issues a cache identifier by which a caller can
>>   reference a previously presented assertion instead of resending it.
>>   Together, these mechanisms enable flexible trust models ranging from
>>   privacy-preserving pseudonymous verification to horizontally-scalable
>>   delegated authentication and PKI-based identity chains.
>>
>> Please reply to this message and indicate whether or not you support
>> adoption
>> of this Internet-Draft by the httpbis WG. Comments to explain your
>> preference
>> are greatly appreciated. Please reply to all recipients of this message
>> and
>> include this message in your response.
>>
>> Authors, and WG participants in general, are reminded of the Intellectual
>> Property Rights (IPR) disclosure obligations described in BCP 79 [2].
>> Appropriate IPR disclosures required for full conformance with the
>> provisions
>> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
>> Sanctions available for application to violators of IETF IPR Policy can be
>> found at [3].
>>
>> Thank you.
>> [1] https://datatracker.ietf.org/doc/bcp78/
>> [2] https://datatracker.ietf.org/doc/bcp79/
>> [3] https://datatracker.ietf.org/doc/rfc6701/
>>
>> The IETF datatracker status page for this Internet-Draft is:
>> https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
>>
>> There is also an HTML version available at:
>> https://www.ietf.org/archive/id/draft-hardt-httpbis-signature-key-08.html
>>
>> A diff from the previous version is available at:
>>
>> https://author-tools.ietf.org/iddiff?url2=draft-hardt-httpbis-signature-key-08
>>
>>
>>