draft-ietf-httpbis-bcp56bis-11, "4.12. Client Authentication"

"...The Basic authentication scheme [RFC7617] MUST NOT be used unless
the underlying transport is authenticated, integrity-protected and
confidential (e.g., as provided the "HTTPS" URI scheme, or another using
TLS). ..."

This actually modifies a SHOULD-level requirement from RFC 7617 -- is
that really the right thing to do here?

Best regards, Julian

Received on Monday, 5 April 2021 16:39:31 UTC