Skip to content

AgentCard signing example cannot be verified as published #2249

Description

@aeoess

Section 8.4 publishes a canonicalization example, a JOSE protected header and an ES256 signature. I checked the canonicalization example independently against the proto presence rules and that part reproduces.

The signature example is not independently checkable, though. There is no verification key published with it, and the jku points to example.com. It also does not say which payload the signature covers. The canonical form in 8.4.1 is for a small fragment, and 8.4.2 only says "given a canonical Agent Card payload".

That means an implementation can test canonicalization, but cannot verify the published signature against anything.

Could the example include the public verification key used for the signature, and state the exact payload it was computed over?

One related detail: the same signature also appears on the full sample AgentCard in 8.5, but the canonical payload for that full card is not published.

For a golden test I think the useful split is:

  • canonical JSON must equal the published canonical form
  • the published signature must verify with the published test key
  • generated ES256 signatures should verify, rather than requiring byte equality unless the signing procedure also fixes the ECDSA nonce

I reproduced this against spec main afda8316.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions