> This is certainly desirable, but just making it a requirement would make pretty much every proxy non-conformant, so that's a big step.
> Would it be sufficient to just encourage use / support of HTTPS with proxies?

I think that's what a SHOULD is made for. Do you think SHOULD would be
too strong here ?

