%% You should probably cite draft-ietf-wimse-http-signature-05 instead of this revision. @techreport{ietf-wimse-http-signature-01, number = {draft-ietf-wimse-http-signature-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/01/}, author = {Joseph A. Salowey and Yaron Sheffer}, title = {{WIMSE Workload-to-Workload Authentication with HTTP Signatures}}, pagetotal = 18, year = , month = , day = , abstract = {The WIMSE architecture defines authentication and authorization for software workloads in a variety of runtime environments, from the most basic ones to complex multi-service, multi-cloud, multi-tenant deployments. This document defines one of the mechanisms to provide workload authentication, using HTTP Signatures. While only applicable to HTTP traffic, the protocol provides end-to-end protection of requests (and optionally, responses), even when service traffic is not end-to-end encrypted, that is, when TLS proxies and load balancers are used. Authentication is based on the Workload Identity Token (WIT).}, }