Re: Port 80 deprecation

"Martin J. Dürst" <duerst@it.aoyama.ac.jp> Mon, 07 June 2021 04:30 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFE463A3580 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 6 Jun 2021 21:30:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.649
X-Spam-Level:
X-Spam-Status: No, score=-7.649 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=itaoyama.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4hW_xDloI7-Z for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 6 Jun 2021 21:30:28 -0700 (PDT)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BAF6D3A357E for <httpbisa-archive-bis2Juki@lists.ietf.org>; Sun, 6 Jun 2021 21:30:28 -0700 (PDT)
Received: from lists by lyra.w3.org with local (Exim 4.92) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1lq6qc-0007K5-GL for ietf-http-wg-dist@listhub.w3.org; Mon, 07 Jun 2021 04:26:48 +0000
Resent-Date: Mon, 07 Jun 2021 04:26:46 +0000
Resent-Message-Id: <E1lq6qc-0007K5-GL@lyra.w3.org>
Received: from titan.w3.org ([128.30.52.76]) by lyra.w3.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <duerst@it.aoyama.ac.jp>) id 1lq6py-0007IU-Nx for ietf-http-wg@listhub.w3.org; Mon, 07 Jun 2021 04:26:09 +0000
Received: from mail-eopbgr1410095.outbound.protection.outlook.com ([40.107.141.95] helo=JPN01-OS2-obe.outbound.protection.outlook.com) by titan.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <duerst@it.aoyama.ac.jp>) id 1lq6ps-0005vL-1d for ietf-http-wg@w3.org; Mon, 07 Jun 2021 04:26:03 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=iHNqlgqP5metbUr52CUNJT4/PczIFlCc8gMQyVIu+9130+6rXM9+ZpQtNDoCYNS2L/eZlUWL55qeAwvfCS+bWf1UatYInBf8HB3K23d+2TZyNuUaItFps6niYWPlVwCioLb5De6+tEYds0VE4g6DtuAdzwq3klLssor/OmMB/35Mb4wvja/Z63pxlChj+70uQm0JFXCnqgbv2Q8FoCt7jSIAIC9PpIdJ0GgHacrjGGdc+7Vyn5zSAX1bxk5NQbkPe0Jz7mEGKdDevO1ss/CosuQRozMvds5Aj8uQIZlR2Em5UM1TPRhKvUesKd+YmWLeLd2tZ6YvD+MXEwusRyqY5A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=olJxo6jeJmQUeNjtzr+kI4MrJxpkmbiKDp4tIqNZmt0=; b=ThnUad40Gdq7DEwBQSHTcAd/thqe0SMHlZAyF8kjDFxZmDwiQuDGhHpWL+ancLretLNEJ3agySPdpe+Uv/vF2KxK1YL/URMbWdxu8F8NeJ1hGBOAhywLGRFObSBZHNBo59m01LCB86ICVGw7HKKwWQ/qm2fA/JfQQOpJXUQoeEelGrlM86lmWUroOrhBDX3nlZ2OSm7GE/0xE9rZY8U/NTuc6KYVd0PqBR5I5UdAewQwfL+ySgZUFsUlvj8pqr24ewGnjEyXP4gotqtQHPr/sicT0zX72iXfmERyTY0Tj7q9tTt3KezhwsUK8TVwpsUcFM7oPRTb7BWtQNL9DCd2mw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=it.aoyama.ac.jp; dmarc=pass action=none header.from=it.aoyama.ac.jp; dkim=pass header.d=it.aoyama.ac.jp; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itaoyama.onmicrosoft.com; s=selector2-itaoyama-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=olJxo6jeJmQUeNjtzr+kI4MrJxpkmbiKDp4tIqNZmt0=; b=eQFaM6BlWRHFXvBwSE08EIWq3BuUbVr8RvCgv98f40pwLe8FCzQrReUFrZkbENDxSstDE2EEdHJOizy1EWV3Np0e24RCjOATbkf+g+QGDvHD2lUhzVnvp3+ABtuG12n54odvl28pTdKN5q4qBZBZU6zBp+E5Tg3rK2L9hE8wSsY=
Authentication-Results: w3.org; dkim=none (message not signed) header.d=none;w3.org; dmarc=none action=none header.from=it.aoyama.ac.jp;
Received: from TYAPR01MB5689.jpnprd01.prod.outlook.com (2603:1096:404:8053::7) by TYCPR01MB6462.jpnprd01.prod.outlook.com (2603:1096:400:77::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.22; Mon, 7 Jun 2021 04:25:28 +0000
Received: from TYAPR01MB5689.jpnprd01.prod.outlook.com ([fe80::7c68:2926:ee00:a511]) by TYAPR01MB5689.jpnprd01.prod.outlook.com ([fe80::7c68:2926:ee00:a511%5]) with mapi id 15.20.4195.030; Mon, 7 Jun 2021 04:25:28 +0000
To: Adrien de Croy <adrien@qbik.com>, Paul Vixie <paul@redbarn.org>
Cc: "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
References: <41fb81f5-4978-f8da-d0de-7af26cd20e74@gmail.com> <em31279999-b222-49d5-8243-8ec47f667f6e@bombadil> <20210603021542.wjwkk7kq4axoterj@family.redbarn.org> <6fb42e70-2e00-f978-fd59-88ce669e1a91@gmail.com> <20210603040515.qqigadhzrzdbozxu@family.redbarn.org> <20210603114324.GE3909@faui48e.informatik.uni-erlangen.de> <YLswO6umk+WCOXd7@lk-perkele-vii2.locald> <20210605180730.zc4reqk7zquu5xen@family.redbarn.org> <em77cdcccc-e469-4888-91c2-a84330e7dbd3@bombadil>
From: "Martin J. Dürst" <duerst@it.aoyama.ac.jp>
Organization: Aoyama Gakuin University
Message-ID: <7c70c0a1-e7af-0f3d-2b28-ec650c431825@it.aoyama.ac.jp>
Date: Mon, 07 Jun 2021 13:25:26 +0900
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0
In-Reply-To: <em77cdcccc-e469-4888-91c2-a84330e7dbd3@bombadil>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-Originating-IP: [133.2.210.39]
X-ClientProxiedBy: TYAPR04CA0023.apcprd04.prod.outlook.com (2603:1096:404:15::35) To TYAPR01MB5689.jpnprd01.prod.outlook.com (2603:1096:404:8053::7)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from [133.2.210.39] (133.2.210.39) by TYAPR04CA0023.apcprd04.prod.outlook.com (2603:1096:404:15::35) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4195.22 via Frontend Transport; Mon, 7 Jun 2021 04:25:28 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: c8bdc710-a349-424c-b01e-08d9296c47c0
X-MS-TrafficTypeDiagnostic: TYCPR01MB6462:
X-Microsoft-Antispam-PRVS: <TYCPR01MB646232909B63C8E3AD2014D2CA389@TYCPR01MB6462.jpnprd01.prod.outlook.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:9508;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: hZqg45qPBIOWzOU7J2x4WA4KS+o5IcIVuvUedjFVj9YMq6+B4Ez30x0TgVZz88fX3qciNEOYJ5sWCBAkhI2Ofr4XgbfcJGQW1ZgEdDRQyloFah1VLuTDCP6lZ+YNpHNXxg5Nz5IoX28FVSnIcTmhCCGM1Chh60ltTXWy62lnMYBAmZwSlhXoI+YMVc38U3YZAF6lx3u3JFoDvPZ4EE4+qL1bBBlvFeEb8Ma9loE8dDZWpBXUyxCIBLnowAj0ZWLiOQGlgelNaCT0RWUh4XAL1aY2GRbSgnE7v/zN/+herTWRe+xSKrMQjrRZllf9dLZ6+r/lqWMGwJ2S9jJ4WHntpHt7gMQYVRBUREsC+ZGw5ue9w/0VgTZeMOufvvfmudXJazvHlDzM1QHuNKdrlOIhzu5ivvOclIS9nU5ayuMM4XnVMx0gSCoydpiex+5ohiUuQHKw1RRxrN1IMEHLg0wAJ9Jd374YkRO3v+dEq/oUdbpo4aAW/32vU6uicx+xZeUMKMz8F4Gosnm9X50qI27hEK0AgCB428qG+KhJo50TyoRylLG6QA7LX9aAji4EtDQ+BOJVQFZgWK6lmXyEVaq+3ARQCRT9TFYNg8OtxOp+B7jHU0X71t2k+1gIXhL3X/FSPMgZK5YK36SnE3gearxvACFjtzP1BA9JnCNQqCk+35pUMVfE7hF9SDbAOeftovnkIkdXbfvGI59pkBYmfCzd+w6PmuIoXBKOKuv6z51SSGS4CFQiW2ceAdnwdXksSbXa
X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:TYAPR01MB5689.jpnprd01.prod.outlook.com;PTR:;CAT:NONE;SFS:(136003)(346002)(366004)(376002)(39840400004)(396003)(8676002)(8936002)(786003)(316002)(36916002)(956004)(2616005)(52116002)(16576012)(31686004)(6706004)(83380400001)(26005)(186003)(16526019)(110136005)(7116003)(53546011)(4326008)(66946007)(66476007)(86362001)(66556008)(31696002)(2906002)(5660300002)(38100700002)(38350700002)(6486002)(478600001)(3940600001)(45980500001)(43740500002);DIR:OUT;SFP:1102;
X-MS-Exchange-AntiSpam-MessageData: TNnEAMlnTGNrQyNgiosJy/3islV/05XSAN3Bl6VTKf5QOEFeVW8e5kESnuKDVuGFJjsxOVwzzkYr5s1ueOZfZP2ZiecVAKstgHfd2diBJfARCpSsArtMLiaxMNj+f3SE9cWwUU/dBzsCOALvpPpPfcsmmkuCHlMnncKeqissEaPY/7qY17PuzhjPCjwS2L8gQvqDVY/tKQjLN+7hdYca5ye2zAc7kyqoSo5Na8ZCFqab9UAzeqIhmRfgZZigma4gQs97T7nlDn3RIf2Pgn9RNt/Ho04nx+KUsMVkZ6Op8dSuE4qfoiW7Y4jC/7kLJlb9LvolrYmn6+laEm6y6x/c/MQ7BnfB+0qj7H9dBpA5mfqJ2s/TTAF8WeniVJLzAqvODP4Ofw6ZpuTY74Olrviyb7vIr3XvkCRfcOcqe1GPSPx5DLFa06JBo0nltoky2RpcRdIBH1e+EfMKMuIINY2ROXzNZzD5oetUA2aTu0la09QeS7VY6g2BmnHVc+ASmLvbsUaKpuDr3IjiMBvgSnltnG7agAwqQ+ATDQHN74uS3d8LlMM4GApELaW4jLw6R16yDSHtUuj3M7RH7Wg1yxlGk11Lvr2gEd3Odha/eQ53ayI7edg6D8KtYxaTZ3UkJkfSxCzx1UszKG7VoVtNFFZQOGdykdQHgnZzpO1gHVJHF5lZvcO1Lbw5b9D7IOmqMSjFDq+N1V/PF+5Bk5GrZt3K57hITOB+EkjSBOK0fa2DeIgEAwNGakKlc6n574S1Msc/8w8yaUPqITCPCw7fm01epNwbasb7ac7wvaREYAgAr7o1YgKvSgeqX3CEkVLt7TJkGU1BvA3fjKt7oG4bXJhRAaDPVqSXNsFnd0k8p1LUIFN6oqcJF1faE21b//aGPz6Wl4lvQYc3Vz6tzkeU1M7KXm+eXKA93+pGblzsktOo1KEBmKrvg9lIg2vv/RTF6gzRGidE1g3Nxw8YnaMMiL2aeoh/FEGd+AMmn4o5Mk65Me6+iPt8iyNb4n86WSCcrwSI9Rw/qCj/ImWLgvRSzro9rSwBsCByMo+0X9DiGusezITLNabxwSbt51mNX2D0vAtfFtTr2yuojE8Cfj1ZXwjye1FtyYWB4hppaCdElGz3i9qPtTAJI5/odzNAWvzveduhgYlYUYQeaoTiAPH//axXFmZIKnwgqOhWavmnzhOrmLeioQrGa4xrSdrctaOS2tE5UFJtuUfdvQf7ZC/MpKazoGhRJAvWtqdZhgqwrxv4BLc8aqoTwfI3JtHSnZowphFta4p2wefkISooTfwX9EAragvjSISbODMP/DtQ6LPffq8H1V2uqJcGPdiZ6da+bWxm
X-OriginatorOrg: it.aoyama.ac.jp
X-MS-Exchange-CrossTenant-Network-Message-Id: c8bdc710-a349-424c-b01e-08d9296c47c0
X-MS-Exchange-CrossTenant-AuthSource: TYAPR01MB5689.jpnprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Jun 2021 04:25:28.7300 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: e02030e7-4d45-463e-a968-0290e738c18e
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: Va2CcdTXOxVOafUDAUlvrsRKBOn66rx9P7BgvLp4QrsyFVRzuvNJRWPQ6daqa8nCkkLJTacl9w//zDboByjLjg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: TYCPR01MB6462
Received-SPF: pass client-ip=40.107.141.95; envelope-from=duerst@it.aoyama.ac.jp; helo=JPN01-OS2-obe.outbound.protection.outlook.com
X-W3C-Hub-DKIM-Status: validation passed: (address=duerst@it.aoyama.ac.jp domain=itaoyama.onmicrosoft.com), signature is good
X-W3C-Hub-Spam-Status: No, score=-8.9
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, MSGID_FROM_MTA_HEADER=0.001, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: titan.w3.org 1lq6ps-0005vL-1d 05d153c032179faea23575ff2f7e2ca3
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Port 80 deprecation
Archived-At: <https://www.w3.org/mid/7c70c0a1-e7af-0f3d-2b28-ec650c431825@it.aoyama.ac.jp>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/38858
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

I wonder if it isn't time to write a small RFC that lists the cases 
where encryption,... isn't appropriate. (Not that I have the expertise 
or the necessary cycles, sorry.)

Regards,   Martin.

On 2021-06-07 12:38, Adrien de Croy wrote:
> 
> I'm waiting for someone to propose https for accessLocation for OCSP
> 
> Then we will have a nice little Gordian knot.
> 
> CRL checks also have to use http.
> 
> 
> ------ Original Message ------
> From: "Paul Vixie" <paul@redbarn.org>
> To: "Ilari Liusvaara" <ilariliusvaara@welho.com>
> Cc: "Toerless Eckert" <tte@cs.fau.de>; "ietf-http-wg@w3.org" 
> <ietf-http-wg@w3.org>
> Sent: 6/06/2021 6:07:30 am
> Subject: Re: Port 80 deprecation
> 
>> just be aware that i can't get a "localhost" certificate from an X.509 
>> CA, and
>> that the overhead of running an in-house CA just to accomplish this 
>> unneccessary
>> purpose so that i can encrypt and decrypt data between processes who 
>> share a CPU,
>> is unthinkable. (the plaintext will be visible inside the process 
>> endpoints, so
>> there are literally not "on-path advesaries" to protect against.)
>>
>> for web-style API's inside a system image or hypervisor, TLS will 
>> mostly not be
>> used. where it is used, global/universal domain names and IP addresses 
>> will have
>> to be used (to get the X.509 CA system to work), or a private CA will 
>> be used.
>> this would be all cost no benefit, so, infinitely bad cost:benefit 
>> ratio. "nope."
>>
>> HTTP over TCP/80 is forever. but we can say something else if 
>> politically nec'y,
>> but that outcome will not change. i've already had to avoid a GoLang 
>> SMTP module
>> which had no non-SMTPS outbound capability and so could not talk to my 
>> private
>> PostFix server. the TLS-uber-alles mantra is going to lead to some 
>> real trouble.
>>
>> -- 
>> Paul Vixie
>>