Re: breaking TLS (Was: Re: multiplexing -- don't do it)

From: Poul-Henning Kamp <phk@phk.freebsd.dk>
Date: Fri, 06 Apr 2012 21:26:08 +0000
To: Willy Tarreau <w@1wt.eu>
cc: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Roberto Peon <grmocg@gmail.com>, Nicolas Mailhot <nicolas.mailhot@laposte.net>, ietf-http-wg@w3.org
Message-ID: <73255.1333747568@critter.freebsd.dk>
In message <20120406211424.GB4336@1wt.eu>, Willy Tarreau writes:

>In my opinion we should let the user decide between GET https:// and
>CONNECT. That solves all issues because admins can let just a short
>whitelist run on CONNECT, with the rest being analyzed.

For reasons of backwards compat, I don't think we'll get rid of
CONNECT any time soon, and since it is also widely used for getting
VPN out through corp perimeters, it will have to be supported by
proxies still.

