- From: Emily Stark <estark@google.com>
- Date: Mon, 26 Feb 2018 13:39:26 -0800
- To: httpbis <ietf-http-wg@w3.org>
- Cc: Ivan Ristic <ivanr@hardenize.com>
- Message-ID: <CAPP_2SZPaHf1mTGYzbucvyPjCh=BrnvxSsAFi2H=T+46bFS=SQ@mail.gmail.com>
This draft includes two changes proposed by Ivan Ristic: (1) The concept of test reports, which report servers can discard but must return a 200 status code for. Can be used by testing clients to check that report servers are accepting reports as expected. https://github.com/httpwg/http-extensions/issues/416 (2) A 'failure-mode' key in violation reports, to indicate whether a report-only or enforced policy triggered the report. https://github.com/httpwg/http-extensions/issues/417 ---------- Forwarded message ---------- From: <internet-drafts@ietf.org> Date: Mon, Feb 26, 2018 at 1:36 PM Subject: New Version Notification for draft-ietf-httpbis-expect-ct-03.txt To: "estark@google.com" <estark@google.com> A new version of I-D, draft-ietf-httpbis-expect-ct-03.txt has been successfully submitted by estark@google.com and posted to the IETF repository. Name: draft-ietf-httpbis-expect-ct Revision: 03 Title: Expect-CT Extension for HTTP Document date: 2018-02-26 Group: httpbis Pages: 19 URL: https://www.ietf.org/internet-drafts/draft-ietf-httpbis- expect-ct-03.txt Status: https://datatracker.ietf.org/doc/draft-ietf-httpbis-expect- ct/ Htmlized: https://tools.ietf.org/html/draft-ietf-httpbis-expect-ct-03 Htmlized: https://datatracker.ietf.org/doc/html/draft-ietf-httpbis- expect-ct-03 Diff: https://www.ietf.org/rfcdiff?url2=draft-ietf-httpbis- expect-ct-03 Abstract: This document defines a new HTTP header, named Expect-CT, that allows web host operators to instruct user agents to expect valid Signed Certificate Timestamps (SCTs) to be served on connections to these hosts. When configured in enforcement mode, user agents (UAs) will remember that hosts expect SCTs and will refuse connections that do not conform to the UA's Certificate Transparency policy. When configured in report-only mode, UAs will report the lack of valid SCTs to a URI configured by the host, but will allow the connection. By turning on Expect-CT, web host operators can discover misconfigurations in their Certificate Transparency deployments and ensure that misissued certificates accepted by UAs are discoverable in Certificate Transparency logs. Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. The IETF Secretariat
Received on Monday, 26 February 2018 21:40:09 UTC