Fedify is a TypeScript framework for building ActivityPub servers. It implements federation details such as HTTP Signatures, JSON-LD processing, WebFinger, inbox and outbox routing, and activity de...
Fedify maintainer here. Agreed on the key handling. The manual warns about this too: Fedify currently has no workflow for rotating the DID’s key or moving an actor to another DID. One distinction for anyone experimenting: the gateway keys that sign HTTP requests on the actor’s behalf are separate server keys, listed in the DID-signed actor document, so replacing them doesn’t change the identity. The DID key is different. A did:key identifier encodes the public key itself, so a new key means a new DID.
On rotation, there’s no concrete design for #413 yet. I expect it to become an umbrella issue, with key rotation as one of its sub-issues. Since a did:key can’t rotate, that will probably mean supporting another DID method or adding some kind of migration mechanism.
Fedify maintainer here. Agreed on the key handling. The manual warns about this too: Fedify currently has no workflow for rotating the DID’s key or moving an actor to another DID. One distinction for anyone experimenting: the gateway keys that sign HTTP requests on the actor’s behalf are separate server keys, listed in the DID-signed actor document, so replacing them doesn’t change the identity. The DID key is different. A
did:keyidentifier encodes the public key itself, so a new key means a new DID.On rotation, there’s no concrete design for #413 yet. I expect it to become an umbrella issue, with key rotation as one of its sub-issues. Since a
did:keycan’t rotate, that will probably mean supporting another DID method or adding some kind of migration mechanism.