Re: HTTP 2.0 in the clear and over TLS

William Chan (陈智昌) <willchan@chromium.org> Mon, 29 July 2013 21:02 UTC

Return-Path: <ietf-http-wg-request@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CBFD421F995B for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 29 Jul 2013 14:02:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.676
X-Spam-Level:
X-Spam-Status: No, score=-9.676 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GWO3n1YsO9sb for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 29 Jul 2013 14:02:10 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) by ietfa.amsl.com (Postfix) with ESMTP id 0491921F9B07 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Mon, 29 Jul 2013 14:01:54 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.72) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1V3uYg-0003cd-O5 for ietf-http-wg-dist@listhub.w3.org; Mon, 29 Jul 2013 21:00:46 +0000
Resent-Date: Mon, 29 Jul 2013 21:00:46 +0000
Resent-Message-Id: <E1V3uYg-0003cd-O5@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.72) (envelope-from <willchan@google.com>) id 1V3uYX-0003aB-9o for ietf-http-wg@listhub.w3.org; Mon, 29 Jul 2013 21:00:37 +0000
Received: from mail-ob0-f174.google.com ([209.85.214.174]) by lisa.w3.org with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16) (Exim 4.72) (envelope-from <willchan@google.com>) id 1V3uYS-0006LO-5g for ietf-http-wg@w3.org; Mon, 29 Jul 2013 21:00:37 +0000
Received: by mail-ob0-f174.google.com with SMTP id wd6so7176336obb.19 for <ietf-http-wg@w3.org>; Mon, 29 Jul 2013 14:00:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=lOxdYEE+l4/7t5TomfVdtI7KejLNO+MXjM4G1F+eSz4=; b=HZKL/UbN03XIKhLRNV+LRZBgmYMymnKzkNPdKv5NYIAfKybfzCnlnI9HjQPgoIp35J xPqYBGCf49rKGBI7argZagkpoHn+W0swPrzeN4zyq59e6KWSC3Lp4PRL2MQsUh6kIot/ GnPc8jDqMgBTZQLoWl4T+cWa5pfbqxnRAW4utxjgoEWUO6B937a5FXdw3fR3dAiLtdrv luKdxE4NEil1t6Cazd0g5ZvU2/r7bxWlzdEtwayHELj0CKjA4dkXyHh1LvC5ieGxFvEB AntZ5Bswjbr+gRfZf3ZuxkK01txT426iHefFoP18SU5XM0ivBcmKma2PS2Q0Wo+8MzYr g1FQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=lOxdYEE+l4/7t5TomfVdtI7KejLNO+MXjM4G1F+eSz4=; b=dYP1StLGzO3tDI1DS8r6xozFV5J55dsqwvVRbRIzE8rqqsp3YpdI3SzeasZYGZm6ac qbEWlHbLy3/CRpO8jfbx7x5g2TegNARQH204236j5Cxh1jZlFRX8aXJZqq3I6hmCzdYq xlGKQNSdzOdjy2XWzLvRmmZQ6sqAn2NyO1EeM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type :x-gm-message-state; bh=lOxdYEE+l4/7t5TomfVdtI7KejLNO+MXjM4G1F+eSz4=; b=B5QjXTsO5re4sd4uFcP3EaQUfw2KoGDjr8I5qCT+gV4bgPNQvqoO6gZVVy7GdFgF2j F8uGFAJd3QXIFsMr5G+3dpCH2Oi4TWkkg78qrSZaume/cQ3Tw14MBE3ZmVDVoon+vcwP bpv/O1m/alH8QoAu9GJpqnmp2sw7cKDlXEdCOEUpaSBlow3p2bAnaDntnsLCAb8dkYju M6ZwVNpUDRN1NzdeAEQeeUQyZBPDOpJcz5oNmgIndcbNJNGBBhmMUQc/n8hQkP+c0pHo vpr3LiuScvx1J0XA6m9Owaq89RaJsoMh1cEt7/hW0+e5+l3VaZdQq3QUaNT1U4bivLFM 0j3A==
MIME-Version: 1.0
X-Received: by 10.42.158.9 with SMTP id f9mr21460217icx.111.1375131605584; Mon, 29 Jul 2013 14:00:05 -0700 (PDT)
Sender: willchan@google.com
Received: by 10.64.23.7 with HTTP; Mon, 29 Jul 2013 14:00:05 -0700 (PDT)
In-Reply-To: <32754_1375115822_51F69A2E_32754_8403_1_5AE9CCAA1B4A2248AB61B4C7F0AD5FB906C6BC40@PEXCVZYM14.corporate.adroot.infra.ftgroup>
References: <32754_1375115822_51F69A2E_32754_8403_1_5AE9CCAA1B4A2248AB61B4C7F0AD5FB906C6BC40@PEXCVZYM14.corporate.adroot.infra.ftgroup>
Date: Mon, 29 Jul 2013 14:00:05 -0700
X-Google-Sender-Auth: aJ9tfPM-sLMHBa_ND4qiDmasbEk
Message-ID: <CAA4WUYhj0-h4MeL7pJC-gq_bZjnj7KHHUv5YQJGkf_7wGkyGFA@mail.gmail.com>
From: "William Chan (陈智昌)" <willchan@chromium.org>
To: "emile.stephan@orange.com" <emile.stephan@orange.com>
Cc: Michael Sweet <msweet@apple.com>, Eliot Lear <lear@cisco.com>, Zhong Yu <zhong.j.yu@gmail.com>, HTTP Working Group <ietf-http-wg@w3.org>
Content-Type: multipart/alternative; boundary="90e6ba21219bdefa0c04e2acc6b5"
X-Gm-Message-State: ALoCoQlKJ5cU42X/+MMw6rdlnIM/KKwtSbshqEWCTMP+HtUUVh7BwvtPsoUZ4PHe2SbKeBCwBbPvQYokKc3EIWrBQ+2cNTK+aV6qQPXlCeYPAVJtE0AxXZ/I2xMcDR8yUPFmeEXuQWY1hmfzn//sF/y3xBfcH/5ssIR5qXieV1fAUEyOG4KT4yNY70ZFXGyLvBI5kPGt39dk
Received-SPF: pass client-ip=209.85.214.174; envelope-from=willchan@google.com; helo=mail-ob0-f174.google.com
X-W3C-Hub-Spam-Status: No, score=-4.3
X-W3C-Hub-Spam-Report: AWL=-1.977, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-1.528, SPF_PASS=-0.001
X-W3C-Scan-Sig: lisa.w3.org 1V3uYS-0006LO-5g bab0e7a7cfd9c58185fcc04a95066f68
X-Original-To: ietf-http-wg@w3.org
Subject: Re: HTTP 2.0 in the clear and over TLS
Archived-At: <http://www.w3.org/mid/CAA4WUYhj0-h4MeL7pJC-gq_bZjnj7KHHUv5YQJGkf_7wGkyGFA@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/18965
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

No one has said otherwise. Please see the section in the spec where we
provide a way to negotiate HTTP/2.0 in the clear via HTTP Upgrade:
http://http2.github.io/http2-spec/#discover-http.


On Mon, Jul 29, 2013 at 9:37 AM, <emile.stephan@orange.com> wrote:

>  Hi,****
>
> ** **
>
> HTTP2 must work in the clear and over TLS. This is required because
> HTTP1.1 and HTTP2 must coexist to ease the migration to HTTP2, and to
> accelerate HTTP2 deployments. ****
>
> ** **
>
> Regards****
>
> Emile****
>
> ** **
>
> *De :* Michael Sweet [mailto:msweet@apple.com <msweet@apple.com>]
> *Envoyé :* dimanche 28 juillet 2013 14:12
> *À :* Eliot Lear
> *Cc :* William Chan (陈智昌) ; Zhong Yu; HTTP Working Group
> *Objet :* Re: HTTPS 2.0 without TLS extension?****
>
> ** **
>
> ... and don't forgot some of the more obscure usage of HTTP, such as HTTP
> over USB in the USB-IF's IPP USB Specification:****
>
> ** **
>
>     http://www.usb.org/developers/devclass_docs****
>
>
>
> ****
>
> There isn't much point in using TLS over USB (and a lot of cost issues for
> that class of printer against it), and we need to continue to use the same
> USB end points/interfaces, so upgrade remains an important feature of
> HTTP/2.0 for me/Apple...****
>
>
>
> ****
>
>
> Sent from my iPad****
>
>
> On 2013-07-28, at 12:46 AM, Eliot Lear <lear@cisco.com> wrote:****
>
>  ** **
>
> On 7/23/13 7:34 PM, William Chan (陈智昌) wrote:****
>
>  FWIW, it seems reasonable to me to have the spec allow HTTPS 2.0 without
> TLS extension. If you want to Upgrade, be my guest. I have no plans for my
> browser to support that, and I don't think Google servers will support it
> either, because we care strongly about the advantages of TLS-ALPN vs
> Upgrade.****
>
>
> Not only that, I don't think we can reasonably call this HTTP 2.0 if we
> have no path to do it in the clear.****
>
>  _________________________________________________________________________________________________________________________
>
> Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
> pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
> a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
> Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
>
> This message and its attachments may contain confidential or privileged information that may be protected by law;
> they should not be distributed, used or copied without authorisation.
> If you have received this email in error, please notify the sender and delete this message and its attachments.
> As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
> Thank you.
>
>