- From: Mark Nottingham <mnot@mnot.net>
- Date: Mon, 19 Apr 2021 17:30:52 +1000
- To: "Julian F. Reschke" <julian.reschke@gmx.de>
- Cc: ietf-http-wg@w3.org
For the scope of this specification (recommendations to IETF-defined standards that use HTTP), I think it is. What do others think? > On 6 Apr 2021, at 2:39 am, Julian Reschke <julian.reschke@gmx.de> wrote: > > "...The Basic authentication scheme [RFC7617] MUST NOT be used unless > the underlying transport is authenticated, integrity-protected and > confidential (e.g., as provided the "HTTPS" URI scheme, or another using > TLS). ..." > > This actually modifies a SHOULD-level requirement from RFC 7617 -- is > that really the right thing to do here? > > Best regards, Julian > -- Mark Nottingham https://www.mnot.net/
Received on Monday, 19 April 2021 07:31:15 UTC