Re: [secdir] additional mechanisms on top of the auth framework, was: SECDIR review of draft-ietf-httpbis-p7-auth-24

On Thu, Oct 31, 2013 at 02:54:45PM +0100, Julian Reschke wrote:
> On 2013-10-29 20:35, Stephen Kent wrote:
> >...
> 
> 
> OK. Maybe:
> 
> "HTTP does not restrict applications to this simple
> challenge-response framework. Additional mechanisms can be used,
> such as additional header fields carrying authentication
> information, or encryption on the transport layer in order to
> provide confidentiality. However, such additional mechanisms are not
> defined by this specification."

Or even -as pretty much all web authentication is done- *above* HTTP.

Nico
-- 

Received on Thursday, 31 October 2013 14:51:33 UTC