Re: [hybi] Extensibility mechanisms?

Justin Erenkrantz <justin@erenkrantz.com> Sat, 17 April 2010 07:13 UTC

Return-Path: <justin.erenkrantz@gmail.com>
X-Original-To: hybi@core3.amsl.com
Delivered-To: hybi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id B7AFF3A6810 for <hybi@core3.amsl.com>; Sat, 17 Apr 2010 00:13:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.327
X-Spam-Level:
X-Spam-Status: No, score=-1.327 tagged_above=-999 required=5 tests=[AWL=0.650, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bh48LwxTwGIt for <hybi@core3.amsl.com>; Sat, 17 Apr 2010 00:13:44 -0700 (PDT)
Received: from mail-qy0-f171.google.com (mail-qy0-f171.google.com [209.85.221.171]) by core3.amsl.com (Postfix) with ESMTP id 2E3E83A67D6 for <hybi@ietf.org>; Sat, 17 Apr 2010 00:13:40 -0700 (PDT)
Received: by qyk1 with SMTP id 1so3298365qyk.15 for <hybi@ietf.org>; Sat, 17 Apr 2010 00:13:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:received:in-reply-to :references:date:x-google-sender-auth:received:message-id:subject :from:to:cc:content-type; bh=Wqp3fxO4ZDg34vn0NATKniOO7wZdFFXAXwBYPePcQzw=; b=CV1tu9wH4ytanMQFqs9mWrJH5CIoPC19FlPofifSPST9+HH8VrCV9SxuOl6Y+crkIe PRuav+Gq792TdGBFFGlgubKFGb2V/nPBHXZznGN9JUsrL56lx9L+g/rybGPy/tbYz7UP BRi1agvFC/faPzDeA6ccIZ976Dl/+h8ch1dBQ=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=fIR61/7M6AIYEqtNgjzH7ycc/A0NQCL2JhnL6GWwxkHukvdV5JJTrWRdpGfBsiDJ8Q HXxQIvNHCdzYwN8SheHYn7uOIeIfDl8Nwpc9sG82U9wW/lstFiDgFsKUlv7Av0QE7A6q goUU9Q27iNiy0mTabOiD8AWpjgiofWZ5CxTLc=
MIME-Version: 1.0
Sender: justin.erenkrantz@gmail.com
Received: by 10.229.17.84 with HTTP; Sat, 17 Apr 2010 00:13:29 -0700 (PDT)
In-Reply-To: <Pine.LNX.4.64.1004161952530.751@ps20323.dreamhostps.com>
References: <h2w5c902b9e1004152345j992b815bz5f8d38f06a19181a@mail.gmail.com> <Pine.LNX.4.64.1004160701250.751@ps20323.dreamhostps.com> <4BC860FD.8080007@webtide.com> <Pine.LNX.4.64.1004161952530.751@ps20323.dreamhostps.com>
Date: Sat, 17 Apr 2010 00:13:29 -0700
X-Google-Sender-Auth: 80f20e3f85b9c851
Received: by 10.229.241.66 with SMTP id ld2mr2000210qcb.78.1271488409922; Sat, 17 Apr 2010 00:13:29 -0700 (PDT)
Message-ID: <r2x5c902b9e1004170013o79f0b998v35a459c3fe648fb1@mail.gmail.com>
From: Justin Erenkrantz <justin@erenkrantz.com>
To: Ian Hickson <ian@hixie.ch>
Content-Type: text/plain; charset="ISO-8859-1"
Cc: Hybi <hybi@ietf.org>
Subject: Re: [hybi] Extensibility mechanisms?
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 17 Apr 2010 07:13:45 -0000

On Fri, Apr 16, 2010 at 1:13 PM, Ian Hickson <ian@hixie.ch> wrote:
> ideal deployment the connection is wrapped in end-to-end TLS, so the
> intermediaries can't do anything with it. There were only two reasons for

It may be appropriate to say it is end-to-end TLS at an organizational
level (ie user to origin), but my experience is that most reverse
proxy deployments perform TLS termination on the edge of the network
so that load balancing techniques can be applied inside the network
without TLS overhead.  So, I believe it is very unlikely to expect
that there will always be end-to-end TLS at scale - the intermediaries
will be relied upon to provide critical load-balancing and failover
mechanisms even for Web Socket.  -- justin