W3C home > Mailing lists > Public > ietf-http-wg@w3.org > January to March 2016

Re: Alt-Svc WGLC

From: Kyle Rose <krose@krose.org>
Date: Mon, 11 Jan 2016 11:05:04 -0500
Message-ID: <CAJU8_nVkibr4DsUOWjpEYOVTPbTdoWyBsgSFiRr7Rp4=qFKjPA@mail.gmail.com>
To: Julian Reschke <julian.reschke@gmx.de>
Cc: Hervé Ruellan <herve.ruellan@crf.canon.fr>, HTTP Working Group <ietf-http-wg@w3.org>
> I just noticed that I failed to reply to this. The proposed change is to
> replace
>
> "Clients MUST NOT use alternative services with a host that is different
> from the origin's without strong server authentication; ...."
>
> by
>
> "Clients MUST NOT use an alternative service with a host that is different
> than the origin's without strong server authentication linking the
> alternative service with the origin's identity. ..."
>
> My remaining concern is that "...linking the alternative service with the
> origin's identity..." might not sufficiently precise for a normative
> requirement. More feedback appreciated.

How about "Clients MUST NOT use an alternative service with a host
that is different from the origin's without strong server
authentication of the alternative service declaration"?

Kyle
Received on Monday, 11 January 2016 16:05:39 UTC

This archive was generated by hypermail 2.3.1 : Tuesday, 22 March 2016 12:47:10 UTC