Re: security requirements (was: Updating RFC 2617 (HTTP Digest) to use UTF-8)

Paul Leach wrote:
> 
> That's because making a protocol feature mandatory-to-implement does NOT
> make it mandatory to configure. Hence, for example, one could not
> deduce, from either an HTTP/1.1 or a new HTTP/1.2 sent by a client, that
> a server can send Basic or Digest challenge and be assured that it will
> be understood by the client.

Not if they implemented an RFC 2616 client.

Received on Sunday, 5 November 2006 06:22:09 UTC