Re: [http-auth] Protocol Action: 'The 'Basic' HTTP Authentication Scheme' to Proposed Standard (draft-ietf-httpauth-basicauth-update-07.txt)

Yoav Nir <ynir.ietf@gmail.com> Tue, 03 March 2015 19:37 UTC

Return-Path: <ynir.ietf@gmail.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C6781A88DA for <http-auth@ietfa.amsl.com>; Tue, 3 Mar 2015 11:37:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A2DPC7dabJu1 for <http-auth@ietfa.amsl.com>; Tue, 3 Mar 2015 11:36:59 -0800 (PST)
Received: from mail-wg0-x22e.google.com (mail-wg0-x22e.google.com [IPv6:2a00:1450:400c:c00::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5429E1A88D7 for <http-auth@ietf.org>; Tue, 3 Mar 2015 11:36:59 -0800 (PST)
Received: by wghl18 with SMTP id l18so42173516wgh.8 for <http-auth@ietf.org>; Tue, 03 Mar 2015 11:36:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=content-type:mime-version:subject:from:in-reply-to:date :content-transfer-encoding:message-id:references:to; bh=6O2RIfnAICBJjjgHMCks8gcxKnIQS2t2mTnhvbIlKko=; b=Eg6pXEN1PrEL7Beeq10dD+IY6iHE59NND9ruVB7/KELi3C/FNa7pUujVbkk95gxCJk LJ/sxSv4WjApp3ewCMpm39vH0LXC2zMuaVh08QzjoUM/HUzlcjfEy7jDgQpGsMH1U6Vj AUpnTJCWjV3Pj3YSS0PEcv6YdY2auNLleNCmLdtvrpVflB14dThxAYhIMoigDo+GK1hs NN7Tgw2SylgHT/WNVYCR3M0hIiardO4tP5lRoEaudJSQmJmeONlZdrUu2BzQA/7TOYbM PZjAazRPfDVzyn3hXcLXrDwjOJzXieJcNKwhHl6h3UKlpwTwqasGke5pnnAfBekCL7uW tFwQ==
X-Received: by 10.194.134.169 with SMTP id pl9mr641643wjb.67.1425411417991; Tue, 03 Mar 2015 11:36:57 -0800 (PST)
Received: from [192.168.1.13] ([46.120.13.132]) by mx.google.com with ESMTPSA id vv9sm2635664wjc.35.2015.03.03.11.36.57 for <http-auth@ietf.org> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 03 Mar 2015 11:36:57 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2070.6\))
From: Yoav Nir <ynir.ietf@gmail.com>
In-Reply-To: <20150303190453.1403.72217.idtracker@ietfa.amsl.com>
Date: Tue, 03 Mar 2015 21:36:55 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <C953CCF3-981A-417E-A26F-FF2419D7CD32@gmail.com>
References: <20150303190453.1403.72217.idtracker@ietfa.amsl.com>
To: httpauth mailing list <http-auth@ietf.org>
X-Mailer: Apple Mail (2.2070.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/http-auth/tfCsJ8mTvmxvKP_CacpD8QwhHH4>
Subject: Re: [http-auth] Protocol Action: 'The 'Basic' HTTP Authentication Scheme' to Proposed Standard (draft-ietf-httpauth-basicauth-update-07.txt)
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Mar 2015 19:37:06 -0000

Congratulations, Julian. Thanks for all the work.  And thanks to all who contributed.

Yoav

> On Mar 3, 2015, at 9:04 PM, The IESG <iesg-secretary@ietf.org> wrote:
> 
> The IESG has approved the following document:
> - 'The 'Basic' HTTP Authentication Scheme'
>  (draft-ietf-httpauth-basicauth-update-07.txt) as Proposed Standard
> 
> This document is the product of the Hypertext Transfer Protocol
> Authentication Working Group.
> 
> The IESG contact persons are Stephen Farrell and Kathleen Moriarty.
> 
> A URL of this Internet Draft is:
> http://datatracker.ietf.org/doc/draft-ietf-httpauth-basicauth-update/
> 
> 
> 
> 
> 
> Technical Summary
> 
>   This document defines the "Basic" Hypertext Transfer Protocol (HTTP)
>   Authentication Scheme, which transmits credentials as userid/password
>   pairs, Base64 encoded. The "Basic" scheme previously was defined in
>   Section 2 of [RFC2617].  This document updates the definition, and also
>   addresses internationalization issues by introducing the "charset"
>   authentication parameter (Section 2.1).
>   This version details all of the known security issues and explicitly
>   discourages it's use when a more secure type of authentication
>   should be used.
> 
> Working Group Summary
> 
>   This document is part of a set of documents that includes HTTP Digest
>   and RFC7235 to collectively obsolete RFC 2617.  As such, this draft
>   describes existing practice, with an update to add support for 
>   internationalization:
>    o A new charset parameter with UTF-8 as the only valid value.
>    o A normative reference to the precis draft for valid characters.
>    o Appendix B with deployment considerations for co-existing with
>      legacy implementations.
> 
>   With version -07 it is the consensus of the HTTP-Auth working group 
>   that this document is fit to be published as a standards-track RFC.
> 
> Document Quality
> 
>   There are a few implementations of this specification, and they have 
>   been tested and shown to interoperate with the large install base of 
>   web browsers and web servers.
> 
> Personnel
> 
>   Kathleen Moriarty is the responsible Area Director.
>   Yoav Nir is the document shepherd.
> 
> IANA Note
> 
>    IANA maintains the registry of HTTP Authentication Schemes
>    ([RFC7235]) at <http://www.iana.org/assignments/http-authschemes>
>    and the entry for the "Basic" Authentication Scheme is to be updated with
>    a pointer to this specification.
>