[Uta] UTA in HTTP

Peter Saint-Andre <stpeter@stpeter.im> Tue, 25 February 2014 00:30 UTC

Return-Path: <stpeter@stpeter.im>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 394441A0200 for <uta@ietfa.amsl.com>; Mon, 24 Feb 2014 16:30:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.449
X-Spam-Level:
X-Spam-Status: No, score=-2.449 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.547, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QzqfC9JCGYWn for <uta@ietfa.amsl.com>; Mon, 24 Feb 2014 16:30:55 -0800 (PST)
Received: from stpeter.im (mailhost.stpeter.im [207.210.219.225]) by ietfa.amsl.com (Postfix) with ESMTP id E08701A02D8 for <uta@ietf.org>; Mon, 24 Feb 2014 16:30:55 -0800 (PST)
Received: from aither.local (unknown [24.8.184.175]) (Authenticated sender: stpeter) by stpeter.im (Postfix) with ESMTPSA id 2282140347; Mon, 24 Feb 2014 17:30:55 -0700 (MST)
Message-ID: <530BE43F.6000305@stpeter.im>
Date: Mon, 24 Feb 2014 17:30:55 -0700
From: Peter Saint-Andre <stpeter@stpeter.im>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.3.0
MIME-Version: 1.0
To: "uta@ietf.org" <uta@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/uta/n2t8OuWfp5zVzk5D-MMcoJ2g6zc
Subject: [Uta] UTA in HTTP
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Feb 2014 00:30:58 -0000

We haven't discussed HTTP much if at all. A few Internet-Drafts seem 
relevant since they touch on some UTA-related topics such as mandatory 
to implement crypto algorithms. See especially:

* Minimal Unauthenticated Encryption (MUE) for HTTP/2
 
https://datatracker.ietf.org/doc/draft-hoffman-httpbis-minimal-unauth-enc/

* Applying Unauthenticated Transport Layer Security (TLS) to Hypertext 
Transport Protocol (HTTP) Connections
   https://datatracker.ietf.org/doc/draft-miller-http-unauth-tls/

I'm sure the authors would appreciate feedback from folks active in the 
UTA WG. I'd be especially curious to know if any of the issues raised in 
those documents might need to be addressed in the tls-bcp document 
(e.g., draft-miller-http-unauth-tls talks about caching the results of 
attempting a TLS connection at a given web origin).

Peter

-- 
Peter Saint-Andre
https://stpeter.im/