RFC 9421: HTTP Message Signatures
In plain English — editorial summary, not part of the RFC
This document describes a mechanism for creating, encoding, and verifying digital signatures or message authentication codes over components of an HTTP message. This mechanism supports use cases where the full HTTP message may not be known to the signer and where the message may be transformed (e.g., by intermediaries) before reaching the verifier. This document also describes a means for requesting that a signature be applied to a subsequent HTTP message in an ongoing HTTP exchange.
Document record
- Document ID
- RFC9421
- Published
- February 2024
- Authors
- A. Backman; J. Richer; M. Sporny
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- wit
- Pages
- 95
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9773ACME Renewal Information (ARI) ExtensionCurrent
June 2025
- RFC 9809X.509 Certificate Extended Key Usage (EKU) for Configuration, Updates, and Safety-Critical CommunicationCurrent
July 2025
- RFC 9810Internet X.509 Public Key Infrastructure -- Certificate Management Protocol (CMP)Current
July 2025
- RFC 9811Internet X.509 Public Key Infrastructure -- HTTP Transfer for the Certificate Management Protocol (CMP)Current
July 2025
- RFC 8737Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge ExtensionCurrent
February 2020
- RFC 8659DNS Certification Authority Authorization (CAA) Resource RecordCurrent
November 2019
- RFC 8555Automatic Certificate Management Environment (ACME)Current
March 2019
- RFC 8410Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key InfrastructureUpdated
August 2018
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?