Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Misleading instructions for signing the signature string #1080

Open
sventiffe opened this issue Nov 24, 2022 · 0 comments
Open

Misleading instructions for signing the signature string #1080

sventiffe opened this issue Nov 24, 2022 · 0 comments

Comments

@sventiffe
Copy link

sventiffe commented Nov 24, 2022

https://docs.joinmastodon.org/spec/security/ instructs for creating the 'Signature' header:

The signature string is then hashed with SHA256 and signed with the actor’s public key.

This meant to be the private key not the public key.

The signature string is then hashed with SHA256 and signed with the actor’s public key.

Speaking for myself, this brought me on the wrong track as it does not mention the need for padding for RSASSA-PKCS1-v1_5. See this discussion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant