Re: Security Requirements for HTTP, draft -00

tis 2008-01-29 klockan 12:18 +1300 skrev Adrien de Croy:

> fundamental design/structure and how it has evolved.  HTTP was initially
> designed to connect, make request, get result and disconnect.  This
> doesn't have room in it for a challenge response auth scheme until you
> move to persistent connections.

Sure it does. Digest is an example of that. Just means that the
authentication session needs to be at the protocol message layer and not
transport connection.

Regards
Henrik

Received on Tuesday, 5 February 2008 12:44:52 UTC