Re: The Hypertext Transfer Protocol (HTTP) Authentication-Info Header Field
Amos Jeffries <squid3@treenet.co.nz> Sat, 31 January 2015 14:08 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C73401A89F1 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sat, 31 Jan 2015 06:08:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qBIn-YpXhYlI for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sat, 31 Jan 2015 06:08:46 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C757B1A89ED for <httpbisa-archive-bis2Juki@lists.ietf.org>; Sat, 31 Jan 2015 06:08:46 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YHYfu-00029Q-Kh for ietf-http-wg-dist@listhub.w3.org; Sat, 31 Jan 2015 14:05:26 +0000
Resent-Date: Sat, 31 Jan 2015 14:05:26 +0000
Resent-Message-Id: <E1YHYfu-00029Q-Kh@frink.w3.org>
Received: from maggie.w3.org ([128.30.52.39]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <squid3@treenet.co.nz>) id 1YHYfn-00028Q-2k for ietf-http-wg@listhub.w3.org; Sat, 31 Jan 2015 14:05:19 +0000
Received: from 121-99-228-82.static.orcon.net.nz ([121.99.228.82] helo=treenet.co.nz) by maggie.w3.org with esmtp (Exim 4.72) (envelope-from <squid3@treenet.co.nz>) id 1YHYfh-0006aw-W4 for ietf-http-wg@w3.org; Sat, 31 Jan 2015 14:05:19 +0000
Received: from [192.168.2.25] (121-98-154-105.bng1.mdr.orcon.net.nz [121.98.154.105]) by treenet.co.nz (Postfix) with ESMTP id 43136E6D9F for <ietf-http-wg@w3.org>; Sun, 1 Feb 2015 03:04:42 +1300 (NZDT)
Message-ID: <54CCE0EC.1010406@treenet.co.nz>
Date: Sun, 01 Feb 2015 03:04:28 +1300
From: Amos Jeffries <squid3@treenet.co.nz>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: ietf-http-wg@w3.org
References: <54C8A44C.8080308@gmx.de> <54C8B2F5.4060506@treenet.co.nz> <54C8C127.4090802@greenbytes.de>
In-Reply-To: <54C8C127.4090802@greenbytes.de>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Received-SPF: pass client-ip=121.99.228.82; envelope-from=squid3@treenet.co.nz; helo=treenet.co.nz
X-W3C-Hub-Spam-Status: No, score=-3.4
X-W3C-Hub-Spam-Report: AWL=-1.528, BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, TVD_RCVD_IP=0.001, URIBL_BLOCKED=0.001
X-W3C-Scan-Sig: maggie.w3.org 1YHYfh-0006aw-W4 50e67e624d0aa5f3a688fa3d9ecb4e92
X-Original-To: ietf-http-wg@w3.org
Subject: Re: The Hypertext Transfer Protocol (HTTP) Authentication-Info Header Field
Archived-At: <http://www.w3.org/mid/54CCE0EC.1010406@treenet.co.nz>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28719
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
On 28/01/2015 11:59 p.m., Julian Reschke wrote: > On 2015-01-28 10:59, Amos Jeffries wrote: >> ... >> I think its a good idea. >> ... > > Thanks. > >> It is also worth noting at this point that those headers are already in >> use in the wild (by Squid at least) for Negotiate scheme in a way that >> does not match the ABNF. Instead they just echo back from the server the >> accepted "Negotiate <token>" credentials received from the client. >> ... > > Well, Negotiate already is that weirdo (see RFC 7236). > > We *could* define Authentication-Info without having an ABNF, but I'd > prefer to stick to what RFC 2617 said (it's flexible enough). > >> I am not sure exactly why Squid does this, I've queried our dev team to >> see if anyone knows. > > Thanks. It's certainly not document in the RFC. In a quick search, I > also found <http://curl.haxx.se/mail/archive-2009-02/0106.html>. > > Best regards, Julian > After some investigation it seems there is no other software out there doing this and we can find no clients making use of it. The curl references all seem to be people operating curl through a Squid. So FYI, I will be removing the odd syntax use from all the upcoming Squid releases (3.5.2 and 3.4.12 onward). Amos
- The Hypertext Transfer Protocol (HTTP) Authentica… Julian Reschke
- Re: The Hypertext Transfer Protocol (HTTP) Authen… Amos Jeffries
- Re: The Hypertext Transfer Protocol (HTTP) Authen… Julian Reschke
- Re: The Hypertext Transfer Protocol (HTTP) Authen… Amos Jeffries
- Re: The Hypertext Transfer Protocol (HTTP) Authen… Julian Reschke