Re: Straw-man charter for http-bis
Paul Hoffman <phoffman@imc.org> Thu, 07 June 2007 15:44 UTC
Return-path: <discuss-bounces@apps.ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com)
by megatron.ietf.org with esmtp (Exim 4.43)
id 1HwKAV-000407-Dz; Thu, 07 Jun 2007 11:44:59 -0400
Received: from discuss by megatron.ietf.org with local (Exim 4.43)
id 1HwKAU-000401-Rq for discuss-confirm+ok@megatron.ietf.org;
Thu, 07 Jun 2007 11:44:58 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
by megatron.ietf.org with esmtp (Exim 4.43) id 1HwKAU-0003zt-IO
for discuss@apps.ietf.org; Thu, 07 Jun 2007 11:44:58 -0400
Received: from balder-227.proper.com ([192.245.12.227])
by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HwKAU-0004nh-3E
for discuss@apps.ietf.org; Thu, 07 Jun 2007 11:44:58 -0400
Received: from [10.20.30.108] (dsl-63-249-108-169.cruzio.com [63.249.108.169])
(authenticated bits=0)
by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l57FisBS003281
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
Thu, 7 Jun 2007 08:44:56 -0700 (MST) (envelope-from phoffman@imc.org)
Mime-Version: 1.0
Message-Id: <p06240871c28dd59e7371@[10.20.30.108]>
In-Reply-To: <6AE049B9045C00064222693F@[10.1.110.5]>
References: <BA772834-227A-4C1B-9534-070C50DF05B3@mnot.net>
<392C98BA-E7B8-44ED-964B-82FC48162924@mnot.net>
<6AE049B9045C00064222693F@[10.1.110.5]>
Date: Thu, 7 Jun 2007 08:44:44 -0700
To: "ietf-http-wg@w3.org Group" <ietf-http-wg@w3.org>,
Apps Discuss <discuss@apps.ietf.org>
From: Paul Hoffman <phoffman@imc.org>
Subject: Re: Straw-man charter for http-bis
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 73734d43604d52d23b3eba644a169745
Cc:
X-BeenThere: discuss@apps.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: general discussion of application-layer protocols
<discuss.apps.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/discuss>,
<mailto:discuss-request@apps.ietf.org?subject=unsubscribe>
List-Post: <mailto:discuss@apps.ietf.org>
List-Help: <mailto:discuss-request@apps.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/discuss>,
<mailto:discuss-request@apps.ietf.org?subject=subscribe>
Errors-To: discuss-bounces@apps.ietf.org
At 3:42 PM -0700 6/6/07, Chris Newman wrote: >1. HTTP Digest Authentication > >The SASL WG appears to have decided that SASL DIGEST-MD5 is not a >useful authentication mechanism for a number of technical reasons. >I would be uncomfortable having a WG spend a lot of time refining >the existing HTTP Digest mechanism based on that experience. >However, documenting the i18n behavior of deployed implementations >sounds like a sensible thing to do. It seems weird to do significant clarification work on 2616 and basically ignore 2617, given the normative reference to the latter. A better option would be to do full clarifications in 2617, including a discussion of the not-clarifiable internationalization issues. One such clarification is a list of the problems of HTTP Digest in the modern world. This probably should not take "a lot of time"; if it does, it means that the clarifications are all the more valuable. HTTP implementers who see a lot of work in 2616bis and nothing in 2617 will not necessarily come to the conclusion that the IETF wants; it would be better to have a 2617bis that says what we want to say. >2. HTTP Security > >Phishing demonstrates that HTTP's present security mechanisms are >not adequate to meet some important requirements of the present >users of the protocol. I would be uncomfortable moving HTTP from >Draft Standard to Standard given this situation. It's likely that >new work on HTTP security mechanisms (as outlined by >draft-hartman-webauth-phishing) is necessary. However, even with >the present security situation, I have no doubt that RFC 2616 is >widely useful and improving the technical clarity of the base >specification is good work that would benefit the Internet >community. The minimum work necessary to make a draft standard >revision of the base specification complete would be to clearly >document the limitations of the presently deployed HTTP security >mechanisms and the fact they are not adequate for all situations. Agree, but... >Beyond that I consider it inappropriate to hold publication of a >useful revision hostage to new security engineering work. That >opinion may not be shared by others on the IESG. Knowing ahead of time whether or not the work of this proposed WG is likely to get smacked down at the end by the IESG would greatly affect the people working on HTTPbis. >Regardless, I would very much like to see forward progress on the >HTTP security situation. draft-hartman-webauth-phishing generated no significant follow-on discussion that I can see (I would be happy to be mistaken). There are little bits of discussion here and there, but no momentum. Without a strong push from the Apps area for this work, I suspect that it will not happen or, if it does happen in a limited fashion, the results will not be widely adopted in implementations. >3. One vs. Two WGs > >I would support the formation of two separate WGs: HTTP and HTTP >security as the people who have appropriate expertise for those >efforts are not identical. Indeed I'd be uncomfortable with a single >WG that was both revising 2616 and designing new HTTP security >mechanisms as the latter may be helped by the attention of security >experts that likely have no interest in the former. Fair enough. >4. Specification Rewrite > >Because the IETF process gives quite a bit of control to the >document editor and design teams, our process allows an alternate >editor to produce a competing specification and ask for a WG >consensus call to adopt that competing specification. This is >discussed in the following IESG Note: > <http://www.ietf.org/IESG/STATEMENTS/Design-Teams.txt> >>From discussions here, I suspect it's unlikely an alternate >>specification would >be adopted by the WG in this case, especially because it might drop >the target status from draft to proposed for the reasons Keith >mentioned. However, this is an important mechanism the keep the >process open. The status of the new document is *much* less important than its correctness and usability to HTTP implementers.
- Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Mark Nottingham
- RE: Straw-man charter for http-bis Larry Masinter
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis -- call for er… Mark Nottingham
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis -- call for er… Julian Reschke
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis -- call for er… Julian Reschke
- Re: Straw-man charter for http-bis -- call for er… Cyrus Daboo
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis -- call for er… Cyrus Daboo
- Re: Straw-man charter for http-bis Alexey Melnikov
- Re: Straw-man charter for http-bis Alexey Melnikov
- Re: Straw-man charter for http-bis Yves Lafon
- Re: Straw-man charter for http-bis -- call for er… Robert Sayre
- Re: Straw-man charter for http-bis Robert Sayre
- Re: Straw-man charter for http-bis -- call for er… Robert Sayre
- Re: Straw-man charter for http-bis -- call for er… Robert Sayre
- Re: Straw-man charter for http-bis Roy T. Fielding
- Re: Straw-man charter for http-bis -- call for er… Henrik Nordstrom
- Re: Straw-man charter for http-bis -- call for er… Henrik Nordstrom
- Re: Straw-man charter for http-bis Robert Sayre
- Re: Straw-man charter for http-bis -- call for er… Robert Sayre
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Mark Nottingham
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Robert Sayre
- RE: Straw-man charter for http-bis -- call for er… Henrik Nordstrom
- Re: Straw-man charter for http-bis Henrik Nordstrom
- Re: Straw-man charter for http-bis Roy T. Fielding
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis John C Klensin
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Robert Sayre
- Re: Straw-man charter for http-bis Chris Newman
- Re: Straw-man charter for http-bis Julian Reschke
- Re: Straw-man charter for http-bis Alexey Melnikov
- Re: Straw-man charter for http-bis Paul Hoffman
- RFC2616 vs RFC2617, was: Straw-man charter for ht… Julian Reschke
- Re: Straw-man charter for http-bis Keith Moore
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Keith Moore
- Re: Straw-man charter for http-bis Julian Reschke
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Julian Reschke
- Re: Straw-man charter for http-bis Paul Hoffman
- Re: Straw-man charter for http-bis Eliot Lear
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Lisa Dusseault
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Stephane Bortzmeyer
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Joe Orton
- Re: Straw-man charter for http-bis Henrik Nordstrom
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… lists
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… lists
- Re: Straw-man charter for http-bis Eliot Lear
- Re: Straw-man charter for http-bis Chris Newman
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Chris Newman
- Re: Straw-man charter for http-bis Henrik Nordstrom
- Re: Straw-man charter for http-bis Lisa Dusseault
- Re: Straw-man charter for http-bis Martin Duerst
- Re: Straw-man charter for http-bis Henrik Nordstrom
- Re: Straw-man charter for http-bis Keith Moore
- Re: Straw-man charter for http-bis Julian Reschke
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Mark Nottingham
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Stephane Bortzmeyer
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Adrien de Croy
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Stephane Bortzmeyer
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… tom.petch
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Keith Moore
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… tom.petch
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Keith Moore
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Mark Nottingham
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Adrien de Croy
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… Chris Newman
- Re: Straw-man charter for http-bis Chris Newman
- Re: Straw-man charter for http-bis Henrik Nordstrom
- Re: Straw-man charter for http-bis der Mouse
- Re: Straw-man charter for http-bis Keith Moore
- Re: RFC2616 vs RFC2617, was: Straw-man charter fo… tom.petch
- Re: Straw-man charter for http-bis Mark Nottingham
- Character encodings in headers [i74][was: Straw-m… Mark Nottingham
- Re: Character encodings in headers [i74][was: Str… Keith Moore
- Re: Character encodings in headers [i74][was: Str… John C Klensin
- Re: Character encodings in headers [i74][was: Str… Clive D.W. Feather
- Re: Character encodings in headers [i74][was: Str… Martin Duerst
- Re: Character encodings in headers [i74][was: Str… Martin Duerst
- Re: Character encodings in headers [i74][was: Str… Mark Nottingham
- Re: Character encodings in headers [i74][was: Str… Martin Duerst
- Re: Character encodings in headers [i74][was: Str… Mark Nottingham
- Re: Character encodings in headers [i74][was: Str… Clive D.W. Feather
- Re: Character encodings in headers [i74][was: Str… Clive D.W. Feather
- Re: Character encodings in headers [i74][was: Str… Keith Moore
- Re: Character encodings in headers [i74][was: Str… der Mouse
- Re: Character encodings in headers [i74][was: Str… Keith Moore
- Re: Character encodings in headers [i74][was: Str… Stefanos Harhalakis
- Re: Character encodings in headers [i74][was: Str… Keith Moore