Fwd: New Version Notification for draft-ietf-httpbis-expect-ct-03.txt

This draft includes two changes proposed by Ivan Ristic:
(1) The concept of test reports, which report servers can discard but must
return a 200 status code for. Can be used by testing clients to check that
report servers are accepting reports as expected.
https://github.com/httpwg/http-extensions/issues/416
(2) A 'failure-mode' key in violation reports, to indicate whether a
report-only or enforced policy triggered the report.
https://github.com/httpwg/http-extensions/issues/417

---------- Forwarded message ----------
From: <internet-drafts@ietf.org>
Date: Mon, Feb 26, 2018 at 1:36 PM
Subject: New Version Notification for draft-ietf-httpbis-expect-ct-03.txt
To: "estark@google.com" <estark@google.com>



A new version of I-D, draft-ietf-httpbis-expect-ct-03.txt
has been successfully submitted by  estark@google.com and posted to the
IETF repository.

Name:           draft-ietf-httpbis-expect-ct
Revision:       03
Title:          Expect-CT Extension for HTTP
Document date:  2018-02-26
Group:          httpbis
Pages:          19
URL:            https://www.ietf.org/internet-drafts/draft-ietf-httpbis-
expect-ct-03.txt
Status:         https://datatracker.ietf.org/doc/draft-ietf-httpbis-expect-
ct/
Htmlized:       https://tools.ietf.org/html/draft-ietf-httpbis-expect-ct-03
Htmlized:       https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-
expect-ct-03
Diff:           https://www.ietf.org/rfcdiff?url2=draft-ietf-httpbis-
expect-ct-03

Abstract:
   This document defines a new HTTP header, named Expect-CT, that allows
   web host operators to instruct user agents to expect valid Signed
   Certificate Timestamps (SCTs) to be served on connections to these
   hosts.  When configured in enforcement mode, user agents (UAs) will
   remember that hosts expect SCTs and will refuse connections that do
   not conform to the UA's Certificate Transparency policy.  When
   configured in report-only mode, UAs will report the lack of valid
   SCTs to a URI configured by the host, but will allow the connection.
   By turning on Expect-CT, web host operators can discover
   misconfigurations in their Certificate Transparency deployments and
   ensure that misissued certificates accepted by UAs are discoverable
   in Certificate Transparency logs.




Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

Received on Monday, 26 February 2018 21:40:09 UTC