Re: security requirements (was: Updating RFC 2617 (HTTP Digest) to use UTF-8)

On 11/4/06, Robert Sayre <sayrer@gmail.com> wrote:
> "An HTTP client MUST NOT send a version for which it is not at least
> conditionally compliant.'
>

Sorry, that's from RFC 2145. The send button was clicked a bit early. :)

In any case, the requirements and semantics of HTTP version numbers
seem clear as a bell to me. I don't see any interpretation that allows
something as radical as the addition of a mandatory security mechanism
without incrementing the version number.

-- 

Robert Sayre

Received on Saturday, 4 November 2006 20:16:56 UTC