Re: [websec] Issue that came up about HSTS

Paul Hoffman <paul.hoffman@vpnc.org> Sat, 27 October 2012 15:55 UTC

Return-Path: <paul.hoffman@vpnc.org>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A813F21F84FC for <websec@ietfa.amsl.com>; Sat, 27 Oct 2012 08:55:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.598
X-Spam-Level:
X-Spam-Status: No, score=-102.598 tagged_above=-999 required=5 tests=[AWL=0.001, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gueNSGWRe5j9 for <websec@ietfa.amsl.com>; Sat, 27 Oct 2012 08:55:33 -0700 (PDT)
Received: from hoffman.proper.com (IPv6.Hoffman.Proper.COM [IPv6:2605:8e00:100:41::81]) by ietfa.amsl.com (Postfix) with ESMTP id D8D8121F84FB for <websec@ietf.org>; Sat, 27 Oct 2012 08:55:32 -0700 (PDT)
Received: from [10.20.30.101] (50-1-50-97.dsl.dynamic.fusionbroadband.com [50.1.50.97]) (authenticated bits=0) by hoffman.proper.com (8.14.5/8.14.5) with ESMTP id q9RFtIHp058596 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Sat, 27 Oct 2012 08:55:19 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 6.2 \(1499\))
From: Paul Hoffman <paul.hoffman@vpnc.org>
In-Reply-To: <70C766B8-FBF5-4421-B6CE-BCE616FC023B@checkpoint.com>
Date: Sat, 27 Oct 2012 08:55:20 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <867E7110-38EB-4739-8FCF-0A5324EA0C26@vpnc.org>
References: <70C766B8-FBF5-4421-B6CE-BCE616FC023B@checkpoint.com>
To: Yoav Nir <ynir@checkpoint.com>
X-Mailer: Apple Mail (2.1499)
Cc: IETF WebSec WG <websec@ietf.org>
Subject: Re: [websec] Issue that came up about HSTS
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 27 Oct 2012 15:55:33 -0000

On Oct 26, 2012, at 11:42 PM, Yoav Nir <ynir@checkpoint.com> wrote:

> draft-ietf-websec-strict-transport-sec is now being edited by the RFC editor. An issue has come up. We need to resolve this quickly, so please read the following and reply to the list with your opinions.

This looks like a useful, harmless addition.

--Paul Hoffman