#puckipedia<nightpool[m]> I don't see a point to validating the digest separately from the signature. I'm not sure what puckipedia's point is. it's possible your http signature library doesn't support validating it though. <- Digests aren't always SHA-256