
HTTP Request Signatures – SANS Internet Storm Center
This weekend, I noticed three related headers being used in requests to some of our honeypots for the first time [1]: Signature-Input Signature-Agent Signature These headers are related to a relatively new feature, HTTP Message Signatures, which was standardized in RFC 9421 in February last year [2]. First, what is the problem…