RE: REAUTHENTICATION REQUIRED

My point is that the server HAS NO WAY to perform a timeout on its own
without someform of state tracking.  By providing a timeout to the
client, the server doesn't need to introduce some other form of
state management.

On Mon, 24 Nov 1997, Paul Leach wrote:

> How the server does it's timeout is completely up to it, or more precisely,
> up to the application that uses the server.
> 
> As far as I can tell, the people who want this have quite well formed ideas
> as to how long the timeout should be, so we don't need to include
> guidelines.
> 
> As to the second suggestion, which I'll call  "2xx Logout", I'm agnostic,
> and await more WG feedback.

Received on Monday, 24 November 1997 10:14:11 UTC