[Rats] Re: draft-ietf-rats-coserv-07 early Httpdir review
Mark Nottingham <mnot@mnot.net> Fri, 28 August 2026 11:23 UTC
Return-Path: <mnot@mnot.net>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 75BCC130F254B; Fri, 28 Aug 2026 04:23:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787916189; bh=wBHBdpl3ukKvgbh9Ue/k1FknzDAtAPzyTD08q/V+yvQ=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=Tc01oNsQ0y6E0Hb3YlThanar5I25rbB7FMmfY5/nST/dGxGltB5QEuU/f3Hi8L0Fe 6tGHTN6ShixNph9DlfelR/U2RdNZBBSkmOYk91VJ7xRE0iO7piaBBEFZTtokuG/yja NBjhvu1W3qLfIWqlzkCg0cqS7ZTgdGvd0XSiZl/o=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=mnot.net header.b="WfabtkvV"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="ZRpy2nYa"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0oXqawf9yz1l; Fri, 28 Aug 2026 04:23:08 -0700 (PDT)
Received: from fhigh-b8-smtp.messagingengine.com (fhigh-b8-smtp.messagingengine.com [202.12.124.159]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BFE4C130F2543; Fri, 28 Aug 2026 04:23:08 -0700 (PDT)
Received: from phl-compute-10.internal (phl-compute-10.internal [10.202.2.50]) by mailfhigh.stl.internal (Postfix) with ESMTP id 422267A00CA; Fri, 28 Aug 2026 07:23:08 -0400 (EDT)
Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-10.internal (MEProxy); Fri, 28 Aug 2026 07:23:08 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm1; t=1787916188; x=1788002588; bh=SWPEMcZr5UtRKxV5IANt5uFRTB87ZEi9mF4NMTr9TWc=; b= WfabtkvVKX98VZjzxPtsVDNsYnNm7pQEZf3NHILK8TWG3jcz+rmepfZcQn9DVBwI qmseZML/C6kDXAI1mXAW8u95acin4owjA7UiFLAhQpgoAxoFMPzXowUrLZXhOT9d 5bRdRuUE7oFRvxSX3JpyWTUH2tyLce2aRkK0vTcJFaauptAcCyQ6SPxBUJrZfvu3 kOt0UBOq/2iV6rskxzWYO3I4IlU3fypmWClzwEM59UyDoQpTdUYu5tSE0g+h86Ia WeFhCuNmbvI9lf1vIqiAZofSBoBU7Ay9jiZvkyY4U249ITzm61Yi//CtMOWM6m5e ygIyG9x/M6RklqX6mQ7D+w==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t=1787916188; x= 1788002588; bh=SWPEMcZr5UtRKxV5IANt5uFRTB87ZEi9mF4NMTr9TWc=; b=Z Rpy2nYacJutxMh5qQMhRexMWMDvqh1D/BvqVtcEcSV3xpRvH0hvL3btYbUrmYosM NM3n/Br3uXd70/nEHWc7ntQNR9IFupipOA2yOBnLc+2Bwddh57ZOyYWtCAAs46QS nxN+qfK7C42K+KgOr6Wkck3V6diNTTI2YCfldPLJb/7eeJj2ISlIjG/wg5VDAhdb rRTtvFQZOcn//sjVvpdhYc6QLgkKN7MO+cPuTUsKCaY8KH82SDlghMR3dVuBKoRq irjh+vfijyEA7Uf6Y/5VUcYixGklxYIzbUR804b6q2Y2vQF0f0pT/1f6LejeOdGG CK1opDnwabNgBbAezlaHw==
X-ME-Sender: <xms:m2-Ratu0Ute-4yS1LOAGSqtJ_UR9gdejtkNaFhdHjOjxIxoOrXZdLA> <xme:m2-Rat05oK491mV5b-0Qpk_nYhc6KNzrTWDNMFDUdPGlABjKtSZDpnCgghPB_qAX0 aRlCdHR-ObMRZTEBH9ceWi6BsT3xufiOQN3o47G7MPBGROYbdPLM-U>
X-ME-Received: <xmr:m2-RamU1v0qHknglC2PlY0YQSLYW3BzH3PIegCGD_OEzFw1thnyZvHFDlbSo4yEPI6CxhXk>
X-ME-Proxy-Cause: dmFkZTE5aMGjBE1lJKT1+2HKv3YCBhaI8/DD9JMCmoxV+uI9D9WibCp4QbVXYXwSy+b0Jv J64qfbeuBSjD8GcWmtOzNH2OWjRX9CAObXe01RSGcPivWp5dzIxWD5+GWiIpo0dhpTDQJN BFkyT5uJRgjHhDXZ9CL/mmTHPRJFSb9SrGJk6oDSf/9V1vBxDcyrSyV5CLRUduWG7O6UFP Ki49hhhXBHtDbqXNfrOigcsZhR/WyW0LGOGvaot8pOibn+irZCazI+XUZ3ChoV7cMmTM2T Hwd8IOOnCJgpvdfUcGiFhVGPnFWOmSgQqqgeonqxikmwOpPgY468G1oUltBCzod+b/PvBX pVS46jJ0AmQ+9a6sS2bB82RMIcHrdyxFHhdQcqOzXeuxPRK6bFs/TeLPH17giIIUj70VjB Y4ZfIj7vIpeZjkrs5fFkRDbMRPWXQEUKFB6fkN59GfjQdcDC6FmOWt0+U0RQfi3HucsI6d CpITChNYPZM5UiKv+MlB6nWPDWI0UbeHzjVpnZCYvHjlsWo6aXkS/p/UFCyP1t6NBBmkW7 P8BahLjU0L/XVaDh/vLBWGWRuuBNZnbNQiV2aHG7+eBEjeyNp1Gdt5pqEH4J69tJyoOmY2 Ho0j8n/Ms9Aa6fZA1FtQWBO7C3Dp1tZvHahxMvHmwq+Q8stMl9ZP7XregJzw
X-ME-Proxy: <xmx:m2-RagJWwlfhAmY6wCd9mxq3f42d456IneV1NMWfuIow41B1dcMF_Q> <xmx:m2-Rag3Zi4vnlzON_7YviiZnHWrHZpSpKHvWIR5hxUDttKA2a3tDMg> <xmx:m2-Rau7sPbWki8dvYCWNvKMGxiceyz0TcoOfXn3OdBu4B1Y58R26zQ> <xmx:m2-Rah8V8e8B2A6SpItA5IQjac4PH51TH8CT8magYpm0xIjGh1ziSA> <xmx:nG-Rahpby3wnocwkXYSR_GPt8IcsQ9088qTWGiJdt0GRqKe8KymbzdbE>
Feedback-ID: ie6694242:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 28 Aug 2026 07:23:06 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
From: Mark Nottingham <mnot@mnot.net>
In-Reply-To: <GV2PR08MB11418E1F1D3D653E3D109C39FEAA02@GV2PR08MB11418.eurprd08.prod.outlook.com>
Date: Fri, 28 Aug 2026 12:23:05 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <D0DA0846-77EB-4174-89C2-6EA81503FCA8@mnot.net>
References: <178676748452.123882.12124109778422691769@dt-datatracker-7c6ddbc678-86d5j> <GV2PR08MB11418D87E12D6A7CBAEB59E03EAA32@GV2PR08MB11418.eurprd08.prod.outlook.com> <492C20B3-1C4F-4AFE-99EA-D8C118A66AA7@mnot.net> <GV2PR08MB11418E1F1D3D653E3D109C39FEAA02@GV2PR08MB11418.eurprd08.prod.outlook.com>
To: Paul Howard <Paul.Howard@arm.com>
X-Mailer: Apple Mail (2.3864.700.51.1.1)
Message-ID-Hash: OYLZLCOG6FNPYYEBGNUIBHQF4WZFZ3VT
X-Message-ID-Hash: OYLZLCOG6FNPYYEBGNUIBHQF4WZFZ3VT
X-MailFrom: mnot@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Lucas Pardue <lucas@lucaspardue.com>, "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>, "draft-ietf-rats-coserv.all@ietf.org" <draft-ietf-rats-coserv.all@ietf.org>, "rats@ietf.org" <rats@ietf.org>, nd <nd@arm.com>, Thomas Fossati <tho.ietf@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Re: draft-ietf-rats-coserv-07 early Httpdir review
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/RE_pvqK4iLP-mh03Q7Qu_AUsniQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>
Hi Paul, > On 24 Aug 2026, at 10:30 am, Paul Howard <Paul.Howard@arm.com> wrote: > > PH> To clarify, the intention here would be to disallow HEAD on the origin server only (admittedly not very clear from my post). Lucas’s original review suggested that this would be a reasonable step. CoSERV providers are not general-purpose web servers, so the constraint on those ought to be valid, but wouldn’t apply to infrastructure. I don't think that helps. On a cache miss the origin 405s; on a hit, an intermediary may well answer the HEAD from what it already has. So what a client sees depends on the state of a cache it can't see -- the requirement doesn't produce any behaviour a client can rely on, it just makes deployments differ from each other. Also, "general-purpose" isn't a property of your intent -- it's a property of what you're deployed on. Go's net/http dispatches HEAD to the GET handler and drops the content; the Java servlet API and most Python frameworks do the same. You'd be asking implementers to disable behaviour their stack gives them for free. And I don't think the underlying rationale holds up. The concern was HEAD giving clients a cheap way to trigger expensive query computation -- but a GET triggers exactly the same work at the origin. Disallowing HEAD doesn't remove that cost, it just removes one of the two ways of asking for it. If the cost of serving queries is a concern, it needs addressing regardless of method. I'd say nothing about HEAD at all. Cheers, -- Mark Nottingham https://mnot.net/
- [Rats] draft-ietf-rats-coserv-07 early Httpdir re… Lucas Pardue via Datatracker
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Paul Howard
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Paul Howard
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Mark Nottingham
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Paul Howard
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Mark Nottingham
- [Rats] Re: draft-ietf-rats-coserv-07 early Httpdi… Paul Howard