Re: [#177] Realm required on challenges

On Tue, 2009-07-07 at 17:42 +1000, Mark Nottingham wrote:
> Not to argue a particular position WRT #177, but using NTLM is  
> probably a bad example, precisely because it does connection  
> authentication -- thereby breaking HTTP's assumption of statelessness.

Oh it surely is a pain. You don't want to know how ugly making NTLM work
through squid (to NTLM offering servers on the internet) was/is. Pretty
hard to imagine HTTP/SMTP w/NTLM too.

That said, it exists, and forcing it to add a empty realm would be
pointless IMO - let alone probably fraught and likely to break clients.


Received on Tuesday, 7 July 2009 11:44:57 UTC