> Which would mean that a non-normative appendix telling the story about  
> the risk related to TRACE (and TRACK) would be helpful.

I added pointers to US-CERT for CONNECT, TRACE, and TRACK. I updated the  
note under these methods to reference those references.

I disagree with the suggestion that this requirement should be moved  
elsewhere as I've already explained before and Jonas has done as well.

Anne van Kesteren

