Re: Past Proposals for HTTP Auth Logout

Robert Sayre wrote:
> On Thu, Jan 7, 2010 at 1:24 PM, Tim <tim-projects@sentinelchicken.org> wrote:
>> I appologize in advance if this is not an appropriate place to ask
>> this question.
> 
> Feel free to ask questions, but this group is not chartered to add
> features to HTTP authentication schemes. The charter is here:
> 
> <http://www.ietf.org/dyn/wg/charter/httpbis-charter.html>

Yes.

>> I'm doing some research and I'm interested in learning about any past
>> proposals to augment HTTP authentication (basic/digest) with a logout
>> feature.
> 
> That would address one shortcoming of those schemes, but they both
> have more fundamental problems. See
> 
> <http://tools.ietf.org/html/draft-ietf-httpbis-security-properties-03#section-2.2>

True as well. But that being said: just because there are many problems 
to solve doesn't mean we shouldn't try one at a time (if (!) it's 
possible to both specify the solutions and deploy them).

BR, Julian

Received on Wednesday, 13 January 2010 13:56:18 UTC