Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleHTTP-006: Not signing Accept-Signature header

Description

The client indicates whether it wants the server to sign the response by sending the Accept-Signature header. However, the header itself must be signed, because otherwise the server has to ignore it. The specification says: "Servers MUST ignore all request headers which hadn't been signed by the client."

Estimated severity

Status
colourRed
titleCritical

Examples

 

Suggested action

Enforceabsolutecompliance with the specification

How communicated

From the experience of UW (app. 5 partners)