<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I (hopefully) made some progress regarding HTTPS signature handling and double-knocking.]]></title><description><![CDATA[<p>I (hopefully) made some progress regarding HTTPS signature handling and double-knocking.</p><p>Current default is to first try <i>draft-cavage-http-signatures-12</i>, then <i>RFC 9421: HTTP Message Signatures</i>. This may be changed later.</p><p>Retry (the second knock) is done, if the first results in a 400, 401 or 403.</p><p>If the peer instance has accepted <i>DC12</i> in the past, the double-knocking will use <i>DC12</i> first, then <i>RFC9421</i>.</p><p>If the peer instance has accepted <i>RFC9421</i> in the past, the double-knocking will use <i>RFC9421</i> first, then <i>DC12</i>.</p><p><a href="https://mammuthus.de/tags/mammuthus" rel="tag">#<span>Mammuthus</span></a> <a href="https://mammuthus.de/tags/fediverse" rel="tag">#<span>Fediverse</span></a> <a href="https://mammuthus.de/tags/activitypub" rel="tag">#<span>ActivityPub</span></a> <a href="https://mammuthus.de/tags/https" rel="tag">#<span>HTTPS</span></a> <a href="https://mammuthus.de/tags/signature" rel="tag">#<span>Signature</span></a></p>]]></description><link>https://forum.pierobosio.it/topic/e563400d-1c68-462a-a772-5ccf717a3e8d/i-hopefully-made-some-progress-regarding-https-signature-handling-and-double-knocking.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 14 Sep 2026 14:41:16 GMT</lastBuildDate><atom:link href="https://forum.pierobosio.it/topic/e563400d-1c68-462a-a772-5ccf717a3e8d.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 12 Sep 2026 20:11:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I (hopefully) made some progress regarding HTTPS signature handling and double-knocking. on Mon, 14 Sep 2026 08:34:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/julian%40activitypub.space">@<span>julian@activitypub.space</span></a></span></p><p>Needs <b>more</b> testing... before RFC9421 could be used first... 😉</p><p>Improving compatibility would be nice.</p><p>Afair i have already seen a NodeBB message using RFC9421, that was successfully verified.</p>]]></description><link>https://forum.pierobosio.it/post/https://mammuthus.de/users/nick/notes/1009</link><guid isPermaLink="true">https://forum.pierobosio.it/post/https://mammuthus.de/users/nick/notes/1009</guid><dc:creator><![CDATA[nick@mammuthus.de]]></dc:creator><pubDate>Mon, 14 Sep 2026 08:34:04 GMT</pubDate></item><item><title><![CDATA[Reply to I (hopefully) made some progress regarding HTTPS signature handling and double-knocking. on Sun, 13 Sep 2026 00:45:04 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://activitypub.space/user/nick%40mammuthus.de" target="_blank" rel="noopener noreferrer">@nick@mammuthus.de</a> shouldn't the double knock be 9421 first, and then cavage-12 on failure?</p>
<p dir="auto">Also cool! I'd love to test NodeBB's implementation against it. &lt;img class="not-responsive emoji" src="<a href="https://activitypub.space/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=5a9b4bf9c7f" target="_blank" rel="noopener noreferrer">https://activitypub.space/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=5a9b4bf9c7f</a>" title=":smile:" /&gt;</p>
]]></description><link>https://forum.pierobosio.it/post/https://activitypub.space/post/2448</link><guid isPermaLink="true">https://forum.pierobosio.it/post/https://activitypub.space/post/2448</guid><dc:creator><![CDATA[julian@activitypub.space]]></dc:creator><pubDate>Sun, 13 Sep 2026 00:45:04 GMT</pubDate></item></channel></rss>