Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id A75521A8860
 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>;
 Fri,  3 Apr 2015 14:21:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.389
X-Spam-Level: 
X-Spam-Status: No, score=-6.389 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001,
 RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001,
 T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id xShmSysF2Yp3
 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>;
 Fri,  3 Apr 2015 14:21:45 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56])
 (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id CF3E81A8775
 for <httpbisa-archive-bis2Juki@lists.ietf.org>;
 Fri,  3 Apr 2015 14:21:45 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.80)
 (envelope-from <ietf-http-wg-request@listhub.w3.org>)
 id 1Ye8yy-00081w-Ea
 for ietf-http-wg-dist@listhub.w3.org; Fri, 03 Apr 2015 21:18:28 +0000
Resent-Date: Fri, 03 Apr 2015 21:18:28 +0000
Resent-Message-Id: <E1Ye8yy-00081w-Ea@frink.w3.org>
Received: from maggie.w3.org ([128.30.52.39])
 by frink.w3.org with esmtp (Exim 4.80)
 (envelope-from <rch@google.com>) id 1Ye8yu-00081B-9S
 for ietf-http-wg@listhub.w3.org; Fri, 03 Apr 2015 21:18:24 +0000
Received: from mail-yk0-f179.google.com ([209.85.160.179])
 by maggie.w3.org with esmtps (TLS1.2:RSA_ARCFOUR_SHA1:128)
 (Exim 4.80) (envelope-from <rch@google.com>) id 1Ye8yt-0001T5-6M
 for ietf-http-wg@w3.org; Fri, 03 Apr 2015 21:18:24 +0000
Received: by ykft189 with SMTP id t189so10148802ykf.1
 for <ietf-http-wg@w3.org>; Fri, 03 Apr 2015 14:17:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to
 :cc:content-type;
 bh=uCEZly8lAeB/DhzknlwUJ+oEpPctjIefWxZTuI67BUc=;
 b=C5G/WTyuQnXj3WQXqXKEXojk17AudLJ2g7dbe+H98CkMyEbXBCAoZSOAWgbSZN1mz0
 fAjMgu6MJcNLeXRCPZPhYtSFjSQDuR2ptj3HSCNGUUav+sqJwOss5HCTKDwO1l02qrd/
 V0ODd19TEGDmtMGIXm6eo01BShywfkGN0LmVsDVi1aCu9qqmV0iItRAwVC7nG99CK0df
 lfQLFSOYeCZayqLGM2vYfJFXMOzdH9UdNgIBJAJ6gmnRx9uyrI5y9PGHSvJHljETn+CA
 sb73AidfIa6uMKiP6coZ3kX02Mgref2k30x35OeRcIalH3hxqD0+xN7NYL4S6S3KSQXS
 NdHw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:mime-version:in-reply-to:references:date
 :message-id:subject:from:to:cc:content-type;
 bh=uCEZly8lAeB/DhzknlwUJ+oEpPctjIefWxZTuI67BUc=;
 b=C9mJK3jwHwPg0Fkpk4oxAi3YhwE+r0OUwxloz5xJeB+tS7ItHDUvzq134JNlTikDiJ
 WAIrB0jWHh9Wra/900RldUL2axIN/RzKBS95lxKMTrRvWDEWXzwZJwgqG87eHMjs4yGq
 osuk0WwGCFWrMLPbsNqM8/JLyxtrUIiG/gx1qsgaiDzBTTMigv2EdexdwVaDqjnHrkts
 HySuxrA8L/IFLFsLpGNVmky/Hw5fcFJIPlN1xaKY++FWyCAvtbCQPr5fMKj2G0xRYO72
 M+GEV9XrUxUVP8KVcry0Rg9uj07i8WgdrrYN5feFKvVh2ZtwnhYK4JKphzeVx8j6z6wF
 5Xuw==
X-Gm-Message-State: ALoCoQmU4IUVHULPkyI7BFs6lqnANHGycy85TCBriVmpODCONJefOnMjckUGEHw2pYsCCKEwuugd
MIME-Version: 1.0
X-Received: by 10.52.94.6 with SMTP id cy6mr2428150vdb.48.1428095876857; Fri,
 03 Apr 2015 14:17:56 -0700 (PDT)
Received: by 10.52.169.202 with HTTP; Fri, 3 Apr 2015 14:17:56 -0700 (PDT)
In-Reply-To: <CAOdDvNq9cp_bAYy_F_1nA0cHNKfxWVEi5uqmDoZiGoyxjtnvZA@mail.gmail.com>
References: <CAJ_4DfS5J0k-G_fY46R=8jJDbppC8EfvAmLCaeccPFudOfFM0g@mail.gmail.com>
 <CABkgnnWXR7H1oZWLLT7ZhoOtPZjVVDnYaqTYACBkoVQ2scrKJA@mail.gmail.com>
 <CAJ_4DfTBn=QZy=219FDsT-+bHyK-9qfcUfgdxAJFZwN=-JUpNQ@mail.gmail.com>
 <CAOdDvNq9cp_bAYy_F_1nA0cHNKfxWVEi5uqmDoZiGoyxjtnvZA@mail.gmail.com>
Date: Fri, 3 Apr 2015 14:17:56 -0700
Message-ID: <CAJ_4DfR-kpiGmdDQXRG85E46jjNtYP82L7NCqWk8gXHy4=wYTw@mail.gmail.com>
From: Ryan Hamilton <rch@google.com>
To: Patrick McManus <mcmanus@ducksong.com>
Cc: Martin Thomson <martin.thomson@gmail.com>,
 "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
Content-Type: multipart/alternative; boundary=20cf307abe9f7212f30512d87b5f
Received-SPF: pass client-ip=209.85.160.179; envelope-from=rch@google.com;
 helo=mail-yk0-f179.google.com
X-W3C-Hub-Spam-Status: No, score=-4.4
X-W3C-Hub-Spam-Report: AWL=-1.583, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7,
 SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: maggie.w3.org 1Ye8yt-0001T5-6M 1dfcf6a7954c155da040ad6ba384f2e2
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Alt-Svc + Proxy Pac
Archived-At: <http://www.w3.org/mid/CAJ_4DfR-kpiGmdDQXRG85E46jjNtYP82L7NCqWk8gXHy4=wYTw@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/29246
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

--20cf307abe9f7212f30512d87b5f
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Fri, Apr 3, 2015 at 2:04 PM, Patrick McManus <mcmanus@ducksong.com>
wrote:

>
> On Fri, Apr 3, 2015 at 4:50 PM, Ryan Hamilton <rch@google.com> wrote:
>
>> Consider the following scenario. There are two servers,
>> internal.example.com and external.example.com. Inside the enterprise
>> access to resources outside the firewall must go through a proxy, wherea=
s
>> resource inside the firewall can go direct. That would lead to a .pac fi=
le
>> like:
>>
>> function FindProxyForURL(url, host) {=E2=80=8B
>>
>> =E2=80=8B  if (host =3D=3D "internal.example.com") {
>>     return "DIRECT";
>>   }
>>   return "PROXY proxy.example.com";
>> }=E2=80=8B
>>
>>
>> If Alt-Svc for internal says, "Alt-Svc: h2=3D"external.exmple.com:443",
>> then =E2=80=8Bthe proxy will say, "Sure, go direct to
>> http://internal.example.com/" but then the browser will connect to
>> external.example.com:443 and will avoid the proxy and the request will
>> hang. This seems a bit unfortunate, but it's not clear that the alternat=
ive
>> is much better, so I'm happy to do this, if that's the consensus of the
>> group.
>>
>
>
> The browser is supposed to validate the alternate service (among other
> things by checking that it has a cert valid for the origin) before using =
it
> and fall back if it is unavailable. So it seems that
> external.example.com:443 could not be validated in your example and if
> perhaps that validation were stale, it should get automagically cleaned u=
p.
>

=E2=80=8BAgreed! When I said, "the request will hang", I meant to say, "the
connection will hang". You're totally right that this won't be a user
facing problem.=E2=80=8B

=E2=80=8BWe won't use the alternative-service but it's not the end of the w=
orld.=E2=80=8B
=E2=80=8B

I would be very cautious about ever changing url based on alt-svc.. alt-svc
> does not change origins or urls. If it did, it would get very hard to
> reason about. but supplying the alt information explicitly seems a lot mo=
re
> interesting.
>

=E2=80=8BAgreed.=E2=80=8B


> Somebody should really write up a I-D for a modern PAC (that could be me,
> but realistically a lot of other things would have to come off the todo
> list first.)
>

=E2=80=8BSGTM. Especially the part about you doing the work :>=E2=80=8B

--20cf307abe9f7212f30512d87b5f
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:trebuche=
t ms,sans-serif"><span style=3D"font-family:arial,sans-serif">On Fri, Apr 3=
, 2015 at 2:04 PM, Patrick McManus </span><span dir=3D"ltr" style=3D"font-f=
amily:arial,sans-serif">&lt;<a href=3D"mailto:mcmanus@ducksong.com" target=
=3D"_blank" class=3D"cremed">mcmanus@ducksong.com</a>&gt;</span><span style=
=3D"font-family:arial,sans-serif"> wrote:</span><br></div><div class=3D"gma=
il_extra"><div class=3D"gmail_quote"><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div di=
r=3D"ltr"><span class=3D""><div class=3D"gmail_extra"><br><div class=3D"gma=
il_quote">On Fri, Apr 3, 2015 at 4:50 PM, Ryan Hamilton <span dir=3D"ltr">&=
lt;<a href=3D"mailto:rch@google.com" target=3D"_blank" class=3D"cremed">rch=
@google.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" styl=
e=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div cl=
ass=3D"gmail_extra"><div class=3D"gmail_quote"><div><div style=3D"font-fami=
ly:&#39;trebuchet ms&#39;,sans-serif;display:inline">Consider the following=
 scenario. There are two servers, <a href=3D"http://internal.example.com" t=
arget=3D"_blank" class=3D"cremed">internal.example.com</a> and <a href=3D"h=
ttp://external.example.com" target=3D"_blank" class=3D"cremed">external.exa=
mple.com</a>. Inside the enterprise access to resources outside the firewal=
l must go through a proxy, whereas resource inside the firewall can go dire=
ct. That would lead to a .pac file like:</div></div><div><div style=3D"font=
-family:&#39;trebuchet ms&#39;,sans-serif;display:inline"><br></div></div><=
/div></div><blockquote style=3D"margin:0 0 0 40px;border:none;padding:0px">=
<div class=3D"gmail_extra"><div class=3D"gmail_quote"><div><font face=3D"mo=
nospace, monospace"><div style=3D"display:inline"><span style=3D"color:rgb(=
0,0,0)">function FindProxyForURL(url, host) {</span>=E2=80=8B</div>=C2=A0</=
font></div></div></div><div class=3D"gmail_extra"><div class=3D"gmail_quote=
"><div><div><font face=3D"monospace, monospace">=E2=80=8B =C2=A0if (host =
=3D=3D &quot;<a href=3D"http://internal.example.com" target=3D"_blank" clas=
s=3D"cremed">internal.example.com</a>&quot;) {</font></div></div></div></di=
v><div class=3D"gmail_extra"><div class=3D"gmail_quote"><div><div><font fac=
e=3D"monospace, monospace">=C2=A0 =C2=A0 return &quot;DIRECT&quot;;</font><=
/div></div></div></div><div class=3D"gmail_extra"><div class=3D"gmail_quote=
"><div><div><font face=3D"monospace, monospace">=C2=A0 }</font></div></div>=
</div></div><div class=3D"gmail_extra"><div class=3D"gmail_quote"><div><div=
><font face=3D"monospace, monospace">=C2=A0 return &quot;PROXY <a href=3D"h=
ttp://proxy.example.com" target=3D"_blank" class=3D"cremed">proxy.example.c=
om</a>&quot;;</font></div></div></div></div><div class=3D"gmail_extra"><div=
 class=3D"gmail_quote"><div><div><font face=3D"monospace, monospace">}=E2=
=80=8B</font></div></div></div></div></blockquote><div class=3D"gmail_extra=
"><div class=3D"gmail_quote"><div><br></div><div><div style=3D"font-family:=
&#39;trebuchet ms&#39;,sans-serif">If Alt-Svc for internal says, &quot;Alt-=
Svc: h2=3D&quot;<a href=3D"http://external.exmple.com:443" target=3D"_blank=
" class=3D"cremed">external.exmple.com:443</a>&quot;, then =E2=80=8Bthe pro=
xy will say, &quot;Sure, go direct to <a href=3D"http://internal.example.co=
m/" target=3D"_blank" class=3D"cremed">http://internal.example.com/</a>&quo=
t; but then the browser will connect to <a href=3D"http://external.example.=
com:443" target=3D"_blank" class=3D"cremed">external.example.com:443</a> an=
d will avoid the proxy and the request will hang. This seems a bit unfortun=
ate, but it&#39;s not clear that the alternative is much better, so I&#39;m=
 happy to do this, if that&#39;s the consensus of the group.</div><div styl=
e=3D"font-family:&#39;trebuchet ms&#39;,sans-serif"></div></div></div></div=
></blockquote></div><br><br></div></span><div class=3D"gmail_extra">The bro=
wser is supposed to validate the alternate service (among other things by c=
hecking that it has a cert valid for the origin) before using it and fall b=
ack if it is unavailable. So it seems that <a href=3D"http://external.examp=
le.com:443" target=3D"_blank" class=3D"cremed">external.example.com:443</a>=
 could not be validated in your example and if perhaps that validation were=
 stale, it should get automagically cleaned up.<br></div></div></blockquote=
><div><br></div><div><div class=3D"gmail_default" style=3D"font-family:&#39=
;trebuchet ms&#39;,sans-serif;display:inline">=E2=80=8BAgreed! When I said,=
 &quot;the request will hang&quot;, I meant to say, &quot;the connection wi=
ll hang&quot;. You&#39;re totally right that this won&#39;t be a user facin=
g problem.=E2=80=8B</div>=C2=A0<div class=3D"gmail_default" style=3D"font-f=
amily:&#39;trebuchet ms&#39;,sans-serif;display:inline">=E2=80=8BWe won&#39=
;t use the alternative-service but it&#39;s not the end of the world.=E2=80=
=8B</div><div class=3D"gmail_default" style=3D"font-family:&#39;trebuchet m=
s&#39;,sans-serif;display:inline">=E2=80=8B</div></div><div><div class=3D"g=
mail_default" style=3D"font-family:&#39;trebuchet ms&#39;,sans-serif;displa=
y:inline"><br></div></div><blockquote class=3D"gmail_quote" style=3D"margin=
:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><=
div class=3D"gmail_extra">I would be very cautious about ever changing url =
based on alt-svc.. alt-svc does not change origins or urls. If it did, it w=
ould get very hard to reason about. but supplying the alt information expli=
citly seems a lot more interesting. </div></div></blockquote><div><br></div=
><div><div class=3D"gmail_default" style=3D"font-family:&#39;trebuchet ms&#=
39;,sans-serif">=E2=80=8BAgreed.=E2=80=8B</div></div><div>=C2=A0</div><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #cc=
c solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_extra">Someb=
ody should really write up a I-D for a modern PAC (that could be me, but re=
alistically a lot of other things would have to come off the todo list firs=
t.)<br></div></div></blockquote><div>=C2=A0</div></div><div class=3D"gmail_=
default" style=3D"font-family:&#39;trebuchet ms&#39;,sans-serif">=E2=80=8BS=
GTM. Especially the part about you doing the work :&gt;=E2=80=8B</div><br><=
/div></div>

--20cf307abe9f7212f30512d87b5f--

