HTTPBis scope: cookies & TLS

Cookies: Yes

At least logically, cookies belong in the base HTTP specs.
But I wouldn't put it as "revising" RFC 2965, just trying to
figure out what to do to accommodate the current situation with regard
to state management in HTTP.

2817/2818: I'm on the side of "separate working group for HTTP security";
not that I don't think it should be handled, but that you're more likely
to make progress with a WG specifically chartered to deal with HTTP
security as a narrower focus.

Larry

Received on Friday, 31 August 2007 15:18:08 UTC