Re: #549: augmented security considerations in p1

On Jan 31, 2014, at 5:24 AM, Michael Sweet wrote:

> My only comment is that here and in 2.7.2 we are referencing RFC 2818, but that reference is informative.
> 
> Shouldn't we be normatively referencing RFC 2818 since we are only updating it and not obsoleting it?

I don't believe so -- the reference is informative because we don't
depend on it for any of our syntax or requirements.  When someone
gets around to updating 2818, that spec will have a normative
reference on this set since it requires https and HTTP.

....Roy

Received on Saturday, 1 February 2014 11:25:07 UTC