Oh, nice! Congrats to mastodon.social for turning on RFC 9421 signature verification. 🎉
Conversation
Notices
-
Embed this notice
mradcliffe (mradcliffe (he/him)@nokoto.org)'s status on Thursday, 23-Oct-2025 04:40:45 JST
mradcliffe
-
Embed this notice
silverpill (silverpill@mitra.social)'s status on Thursday, 23-Oct-2025 04:40:43 JST
silverpill
@mradcliffe How do you know? They still send me requests with Cavage-Draft signatures
-
Embed this notice
silverpill (silverpill@mitra.social)'s status on Friday, 24-Oct-2025 02:43:42 JST
silverpill
@mradcliffe By the way, it looks like sometimes your comments are delivered twice.
One has id like https://nokoto.org/user/3/posts/611
And another has id like https://nokoto.org/node/611(Maybe they have different types? I didn't check)
Also, I think the attachment in this Article is not quite right: https://nokoto.org/content/jambalaya-shoppe-best-shoppe?_format=activityjson
The Image has href property but normally url is used in media attachment (href is a property of Link).
-
Embed this notice
mradcliffe (mradcliffe (he/him)@nokoto.org)'s status on Friday, 24-Oct-2025 02:43:45 JST
mradcliffe
Sorry, to clarify, I meant mastodon.social is now verifying signatures from remote instances that sign using RFC 9421, @silverpill.
Signing requests is still pending. Unfortunately that seems to have slipped from 4.5.
I configured a debug log to check whether my signature is verified using RFC 9421. So far, Mastodon (for instances that turned the feature on), WordPress and Mitra :-).
In conversation permalink
-
Embed this notice