Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Amos Jeffries <squid3@treenet.co.nz> Thu, 29 January 2015 03:06 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 551D01A8AE8 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 28 Jan 2015 19:06:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.312
X-Spam-Level:
X-Spam-Status: No, score=-6.312 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_66=0.6, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nr2l0s8_UiCv for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 28 Jan 2015 19:06:52 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB4DC1A8AE7 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Wed, 28 Jan 2015 19:06:51 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YGfNM-0002fS-3p for ietf-http-wg-dist@listhub.w3.org; Thu, 29 Jan 2015 03:02:36 +0000
Resent-Date: Thu, 29 Jan 2015 03:02:36 +0000
Resent-Message-Id: <E1YGfNM-0002fS-3p@frink.w3.org>
Received: from maggie.w3.org ([128.30.52.39]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <squid3@treenet.co.nz>) id 1YGfNG-0002eJ-8Y for ietf-http-wg@listhub.w3.org; Thu, 29 Jan 2015 03:02:30 +0000
Received: from 121-99-228-82.static.orcon.net.nz ([121.99.228.82] helo=treenet.co.nz) by maggie.w3.org with esmtp (Exim 4.72) (envelope-from <squid3@treenet.co.nz>) id 1YGfNE-0007nD-VJ for ietf-http-wg@w3.org; Thu, 29 Jan 2015 03:02:29 +0000
Received: from [192.168.2.25] (121-98-154-105.bng1.mdr.orcon.net.nz [121.98.154.105]) by treenet.co.nz (Postfix) with ESMTP id 9164BE6D9F for <ietf-http-wg@w3.org>; Thu, 29 Jan 2015 16:01:54 +1300 (NZDT)
Message-ID: <54C9A29B.2000307@treenet.co.nz>
Date: Thu, 29 Jan 2015 16:01:47 +1300
From: Amos Jeffries <squid3@treenet.co.nz>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: ietf-http-wg@w3.org
References: <1BA93C83-91E9-4E7D-88CE-ADC8C39091C6@mnot.net> <CABkgnnXhg55e5N2O8yZJpTbz4qSm0-KpVApyDha_snetrFqvMw@mail.gmail.com> <CAMeZVwsusptB9dyFYpdue0wKp6wumt73CXYktWURQiuf156J8g@mail.gmail.com>
In-Reply-To: <CAMeZVwsusptB9dyFYpdue0wKp6wumt73CXYktWURQiuf156J8g@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Received-SPF: pass client-ip=121.99.228.82; envelope-from=squid3@treenet.co.nz; helo=treenet.co.nz
X-W3C-Hub-Spam-Status: No, score=-2.4
X-W3C-Hub-Spam-Report: AWL=-2.419, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, TVD_RCVD_IP=0.001
X-W3C-Scan-Sig: maggie.w3.org 1YGfNE-0007nD-VJ e8d3d2a4dba44665db47d35e061bac3d
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Archived-At: <http://www.w3.org/mid/54C9A29B.2000307@treenet.co.nz>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28702
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
On 29/01/2015 2:25 p.m., Yutaka OIWA wrote: > 2015-01-29 9:21 GMT+09:00 Martin Thomson: >> More fundamentally, I see a correlation issue if clients provide >> multiple *Authorization header fields. The response they receive will >> contain some unaggregated name-value pairs in this header field. > > RFC7235 says that HTTP clients can send only one > "credentials" set in the Authorization: or Proxy-authorization: header, > as defined in Sections 4.2 and 4.4. > One "credentials" belongs to a single scheme. > So, "the applicable authentication scheme" means that > the unique scheme which the client has included in the corresponding request. > > Of course, I've wished if the existing Digest authentication scheme had > included an "auth-scheme" in the existing Authentication-Info: header. > If it had a syntax like "Authentication-Info: Digest ...", it would be > self-contained and more clearer. > It's already in use (as a Digest-scheme specific header), and > it cannot be changed without inter-op issues. > Theres nothing stopping a scheme=Digest parameter being specified or sent in that header. It just wont be used by legacy implementations is all. Would be worth bringing up to teh httpauth WG before they seal the next Digest version in stone if its that important to you. Amos
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Alexey Melnikov
- Call for adoption: draft-reschke-httpauth-auth-in… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Martin Thomson
- Re: Call for adoption: draft-reschke-httpauth-aut… Yutaka OIWA
- Re: Call for adoption: draft-reschke-httpauth-aut… Amos Jeffries
- Re: Call for adoption: draft-reschke-httpauth-aut… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Yutaka OIWA
- Re: Call for adoption: draft-reschke-httpauth-aut… Hervé Ruellan
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Rifaat Shekh-Yusef
- Re: Call for adoption: draft-reschke-httpauth-aut… Amos Jeffries
- Re: Call for adoption: draft-reschke-httpauth-aut… Bjoern Hoehrmann
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Bjoern Hoehrmann
- Re: Call for adoption: draft-reschke-httpauth-aut… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Rifaat Shekh-Yusef
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke