Re: security requirements (was: Updating RFC 2617 (HTTP Digest) to use UTF-8)

On 10/18/06, Julian Reschke <julian.reschke@gmx.de> wrote:
> Roy T. Fielding wrote:
> >
> > So, if anyone thinks that a secure authentication scheme is a cool
> > thing, they should propose one and eventually update RFC 2617 to
> > include it, at which point it will be an OPTIONAL secure auth
> > mechanism for HTTP/1.1
>
> I think that makes it clear that a revision of HTTP/1.1 can't make that
> change

I agree.

-- 

Robert Sayre

Received on Wednesday, 18 October 2006 18:32:54 UTC