Separate out HTTP signatures from the message signing spec

Issue #709 new
Dave Tonge created an issue

We discussed on the call today and agree to take the http sig part of message signing out to a sep spec.

This is because it is slowing us down in moving to final with message signing and is not an immediate requirement of any of the ecosystems looking at FAPI 2 (as far as we know)