additional mechanisms on top of the auth framework, was: SECDIR review of draft-ietf-httpbis-p7-auth-24

On 2013-10-29 20:35, Stephen Kent wrote:
 > ...
 > Later on page 6 the text says:
>
> The HTTP protocol does not restrict applications to this simple
>
> challenge-response framework for access authentication.Additional
>
> mechanisms MAY be used, such as encryption at the transport level or
>
> via message encapsulation, and with additional header fields
>
> specifying authentication information.However, such additional
>
> mechanisms are not defined by this specification.
>
> Encryption is not, per se, an authentication mechanism. Please revise
> this text.
> ...


OK. Maybe:

"HTTP does not restrict applications to this simple challenge-response 
framework. Additional mechanisms can be used, such as additional header 
fields carrying authentication information, or encryption on the 
transport layer in order to provide confidentiality. However, such 
additional mechanisms are not defined by this specification."

?

Best regards, Julian

Received on Thursday, 31 October 2013 13:55:10 UTC