- From: Walter H. <Walter.H@mathemainzel.info>
- Date: Sun, 07 Aug 2016 22:03:55 +0200
- To: Kari hurtta <hurtta-ietf@elmme-mailer.org>
- CC: "ietf-http-wg@w3.org" <ietf-http-wg@w3.org>
- Message-ID: <57A7942B.9000600@mathemainzel.info>
On 07.08.2016 21:07, Kari hurtta wrote: > > Yes, content was > > https://lists.w3.org/Archives/Public/ietf-http-wg/2016JulSep/0367.html > > | In our customer base, the biggest driver to deploy MitM is the refusal > | of browsers to display block pages from denied CONNECT requests. > > > https://mnot.github.io/I-D/proxy-explanation/ > does not require MITM. of course not; and the result will be the same ... > That can be show when CONNECT fails and tunneled TLS > is not established. not really; when the proxy refuse connections without MITM, then the result the proxy replies is nearly the same and the result the browser does also ... when the agent is too stupid to present this HTTP/1.1 403 Forbidden Content-Type: text/html Cache-Control: no-cache <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <HTML> <HEAD> <META HTTP-EQUIV="Content-Type"CONTENT="text/html; charset=iso-8859-1"> <TITLE>Policy Violation</TITLE> /HEAD> <BODY> <H1>Policy Violation</H1> <UL> <LI>This content is above your pay grade.<A HREF="https://acme.example.com/why?https://www.example.net" <https://acme.example.com/why?https://www.example.net>>More Info</A>. </LI> </UL> <HR> <ADDRESS>Acme Networks Proxy</ADDRESS> </BODY> </HTML> it won't present this: HTTP/1.1 403 Forbidden Content-Type: application/proxy-explanation+json Cache-Control: no-cache { "name": "Acme Networks" "title": "Policy Violation" "description": "This content is above your pay grade." "moreinfo": "https://acme.example.com/why?https://www.example.net" } too; no difference; the error the proxy replies could also be the following: HTTP/1.1 403 Forbidden Content-Type: text/plain Cache-Control: no-cache Acme Networks Proxy says: "Policy Violation" Because: This content is above your pay grade. For more informations see: https://acme.example.com/why?https://www.example.net Walter
Attachments
- application/pkcs7-signature attachment: S/MIME Cryptographic Signature
Received on Sunday, 7 August 2016 20:06:38 UTC