- From: Mark Nottingham <mnot@mnot.net>
- Date: Tue, 15 Oct 2013 11:50:04 -0700
- To: Eliot Lear <lear@cisco.com>
- Cc: "ietf-http-wg@w3.org Group" <ietf-http-wg@w3.org>
On 15/10/2013, at 4:42 AM, Eliot Lear <lear@cisco.com> wrote: > From a security perspective this is an improvement over draft-nottingham-http2-encryption. Is the intent, therefore, to retire that draft? No; that draft will be pared down to just a proposal to use ALPN protocol identifiers in a different way, to achieve the effect of using TLS for "http://" URIs. Should be updated today. > It does seem that someone should answer the question, "Why not use DNS for this?" There's even a reasonable answer, which is that because this is a header, you are piggybacking it with data. And so it has been done. -- Mark Nottingham http://www.mnot.net/
Received on Tuesday, 15 October 2013 18:50:29 UTC