- From: Julian Reschke <julian.reschke@gmx.de>
- Date: Thu, 31 May 2012 15:39:30 +0200
- To: Mark Nottingham <mnot@mnot.net>
- CC: HTTP Working Group <ietf-http-wg@w3.org>
On 2012-05-31 14:09, Mark Nottingham wrote: > <http://trac.tools.ietf.org/wg/httpbis/trac/ticket/348> > > Proposal - > > New section in p7 Security Considerations: > > """ > 6.2 Protection Spaces > > Authentication schemes that use the "realm" mechanism for establishing a protection space will expose credentials to all resources on a server. This makes it possible for a resource to harvest authentication credentials for other resources on the same server. > > This is of particular concern when a servers hosts resources for multiple parties. Possible mitigation strategies include restricting direct access to authentication credentials (i.e., not making the content of the Authorization request header available), and separating protection spaces by using a different hostname for each party. > """ Works for me. Best regards, Julian
Received on Thursday, 31 May 2012 13:40:08 UTC