Fedify 2.4.0: FEP-ef61 portable objects, background tasks, media uploads, and inbox request reports
Remote
洪 民憙 (Hong Minhee)
@hongminhee@lemmy.ml
A software engineer from Seoul. An advocate of F/OSS, fediverse, and cypherpunk. Hack into East Asian languages.
0 Followers
0 Following
3 Posts
Joined February 17, 2024
Open post
Replying to
Fedify maintainer here. Agreed on the key handling. The manual warns about this too: Fedify currently has no workflow for rotating the DID’s key or moving an actor to another DID. One distinction for anyone experimenting: the gateway keys that sign HTTP requests on the actor’s behalf are separate server keys, listed in the DID-signed actor document, so replacing them doesn’t change the identity. The DID key is different. A did:key identifier encodes the public key itself, so a new key means a new DID.
On rotation, there’s no concrete design for #413 yet. I expect it to become an umbrella issue, with key rotation as one of its sub-issues. Since a did:key can’t rotate, that will probably mean supporting another DID method or adding some kind of migration mechanism.
0
0
0
0