洪 民憙 (Hong Minhee)

A software engineer from Seoul. An advocate of F/OSS, fediverse, and cypherpunk. Hack into East Asian languages.

https://hongminhee.org/

  • 1 Post
  • 1 Comment
Joined 3 years ago
cake
Cake day: February 17th, 2024

help-circle
  • Fedify maintainer here. Agreed on the key handling. The manual warns about this too: Fedify currently has no workflow for rotating the DID’s key or moving an actor to another DID. One distinction for anyone experimenting: the gateway keys that sign HTTP requests on the actor’s behalf are separate server keys, listed in the DID-signed actor document, so replacing them doesn’t change the identity. The DID key is different. A did:key identifier encodes the public key itself, so a new key means a new DID.

    On rotation, there’s no concrete design for #413 yet. I expect it to become an umbrella issue, with key rotation as one of its sub-issues. Since a did:key can’t rotate, that will probably mean supporting another DID method or adding some kind of migration mechanism.