Re: HTTPS, proxy environment variables and non-CONNECT access
"Nicolas Mailhot" <nicolas.mailhot@laposte.net> Tue, 16 July 2013 08:37 UTC
Return-Path: <ietf-http-wg-request@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 17BFD11E826C for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 16 Jul 2013 01:37:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fniu6OPuN9Cl for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 16 Jul 2013 01:36:56 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) by ietfa.amsl.com (Postfix) with ESMTP id 3583D11E8268 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 16 Jul 2013 01:36:56 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.72) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1Uz0jg-0000d0-2T for ietf-http-wg-dist@listhub.w3.org; Tue, 16 Jul 2013 08:35:52 +0000
Resent-Date: Tue, 16 Jul 2013 08:35:52 +0000
Resent-Message-Id: <E1Uz0jg-0000d0-2T@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.72) (envelope-from <nicolas.mailhot@laposte.net>) id 1Uz0jW-0000ap-Fm for ietf-http-wg@listhub.w3.org; Tue, 16 Jul 2013 08:35:42 +0000
Received: from smtpout7.laposte.net ([193.253.67.232] helo=smtpout.laposte.net) by lisa.w3.org with esmtp (Exim 4.72) (envelope-from <nicolas.mailhot@laposte.net>) id 1Uz0jU-0001BA-LK for ietf-http-wg@w3.org; Tue, 16 Jul 2013 08:35:42 +0000
Received: from arekh.dyndns.org ([88.174.226.208]) by mwinf8514-out with ME id 0wbD1m0024WQcrc03wbD9x; Tue, 16 Jul 2013 10:35:13 +0200
Received: from localhost (localhost [127.0.0.1]) by arekh.dyndns.org (Postfix) with ESMTP id D05C32E12C6; Tue, 16 Jul 2013 10:35:12 +0200 (CEST)
X-Virus-Scanned: amavisd-new at arekh.dyndns.org
Received: from arekh.dyndns.org ([127.0.0.1]) by localhost (arekh.okg [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5BEukq5DR4YP; Tue, 16 Jul 2013 10:35:11 +0200 (CEST)
Received: from arekh.dyndns.org (localhost [127.0.0.1]) by arekh.dyndns.org (Postfix) with ESMTP; Tue, 16 Jul 2013 10:35:11 +0200 (CEST)
Received: from 192.196.142.21 (SquirrelMail authenticated user nim) by arekh.dyndns.org with HTTP; Tue, 16 Jul 2013 10:35:11 +0200
Message-ID: <d7ed4bf5bf3c9aa0cad0f9bb2296dc53.squirrel@arekh.dyndns.org>
In-Reply-To: <CAJ3HoZ3ZuBwAZWrsgrZkoBejeH0t0uJRWAdiy1eKKbQwM3xx5g@mail.gmail.com>
References: <CAJ3HoZ3ZuBwAZWrsgrZkoBejeH0t0uJRWAdiy1eKKbQwM3xx5g@mail.gmail.com>
Date: Tue, 16 Jul 2013 10:35:11 +0200
From: Nicolas Mailhot <nicolas.mailhot@laposte.net>
To: Robert Collins <robertc@squid-cache.org>
Cc: HTTP Working Group <ietf-http-wg@w3.org>
User-Agent: SquirrelMail/1.4.22-10.fc19
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
Received-SPF: pass client-ip=193.253.67.232; envelope-from=nicolas.mailhot@laposte.net; helo=smtpout.laposte.net
X-W3C-Hub-Spam-Status: No, score=-3.5
X-W3C-Hub-Spam-Report: AWL=-3.073, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.421, SPF_PASS=-0.001
X-W3C-Scan-Sig: lisa.w3.org 1Uz0jU-0001BA-LK c0e9b5945e9cf76671dd510df105ded6
X-Original-To: ietf-http-wg@w3.org
Subject: Re: HTTPS, proxy environment variables and non-CONNECT access
Archived-At: <http://www.w3.org/mid/d7ed4bf5bf3c9aa0cad0f9bb2296dc53.squirrel@arekh.dyndns.org>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/18800
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
Le Mar 16 juillet 2013 08:08, Robert Collins a écrit : > So [fairly recently] squid and other proxies can retrieve resources > over HTTPS. However user agents generally don't take advantage of > this, instead using CONNECT, to do end to end encryption. Is there a spec somewhere on how it's supposed to work ? > I'm sure that implementing this will start to raise issues like 'how > do we signal client certificates indirectly' and so on, which *will* > be HTTP protocol issues, but one step at a time. Some more questions: 1. How do you protect the client <-> proxy link? 2. how do you send auth from the client to the proxy in a secure way without it leaking them outside? (some http_proxy users just add proxy auth headers everywhere even when the proxy didn't ask for them, in basic auth, so they are leaking secrets to the outside like sieves) 3. more generally how are the client and proxy supposed to distinguish between client <-> proxy signaling and client <-> web site signaling ? 4. Is proxy chaining possible? (I've seen proxy used both to authorize connexions to the outside, and as gateway for connexions inside. So how can a poor user that needs access to a resource protected by and Internet-to-inside proxy traverse his own inside-to-Internet gateway to reach it?) Regards, -- Nicolas Mailhot
- HTTPS, proxy environment variables and non-CONNEC… Robert Collins
- Re: HTTPS, proxy environment variables and non-CO… Nicolas Mailhot
- Re: HTTPS, proxy environment variables and non-CO… Robert Collins
- Re: HTTPS, proxy environment variables and non-CO… Nicolas Mailhot
- Re: HTTPS, proxy environment variables and non-CO… Robert Collins