Re: SSL Tunneling; Informational RFC; Last call?

>	Does anyone familiar with the CONNECT method have a serious
>objection to its being considered as a standards track method, not
>necessarily for the impending HTTP/1.1 RFC, but eventually to be
>merged into an HTTP RFC?

I have no objection to it, provided that the security concerns are
adequately described, but in that case it should not be published as
an Informational RFC (since that is not standards track).  Instead,
it should be submitted to the WG for addition to HTTP/1.1 (assuming
Larry agrees that it is appropriate to do so).

BTW, it is also implemented in the Apache proxy, but I don't know
if that implementation works correctly yet.

....Roy

Received on Friday, 19 September 1997 18:57:24 UTC