RE: [www-p3p-policy] <none>

Hi, fyi...

(from: http://msdn.microsoft.com/library/default.asp?url=/workshop/security/privacy/overview/privacyfaq.asp)

Q: The W3C states that a compact policy header is optional, but cookies do not seem to work without it. Is a compact policy header required?
Answer: Although compact policies are optional for P3P compliance, they are required by Microsoft Internet Explorer to determine the Web site's privacy practices concerning cookies.

Also, Apache supplies a facility for setting additional headers - mod_header.

-----Original Message-----
From: Rigo Wenning [mailto:rigo@w3.org]
Sent: Monday, October 01, 2001 10:11 AM
To: www-p3p-policy@w3.org
Subject: [www-p3p-policy] <none>


>From rigo  Mon Oct  1 15:06:22 2001
Return-path: <rigo@tux.w3.org>
Envelope-to: rigo@localhost
Delivery-date: Mon, 01 Oct 2001 15:06:22 +0200
Received: from localhost ([127.0.0.1])
	by localhost with esmtp (Exim 3.32 #1 (Debian))
	id 15o2m1-0000Cx-00
	for <rigo@localhost>; Mon, 01 Oct 2001 15:06:17 +0200
Received: from www49.inria.fr [138.96.10.12]
	by localhost with POP3 (fetchmail-5.8.3)
	for rigo@localhost (single-drop); Mon, 01 Oct 2001 15:06:17 +0200 (CEST)
Received: from sophia.inria.fr by www49.inria.fr (8.11.1/8.10.0) with ESMTP id f8T4ju128022 for <rwenning@www49.inria.fr>; Sat, 29 Sep 2001 06:45:56 +0200 (MET DST)
Received: from tux.w3.org by sophia.inria.fr (8.11.1/8.10.0) with ESMTP id f8T4kdw21852 for <Rigo.Wenning@sophia.inria.fr>; Sat, 29 Sep 2001 06:46:39 +0200 (MET DST)
Received: (from rigo@localhost)
	by tux.w3.org (8.9.3/8.9.3) id AAA17497
	for Rigo.Wenning@sophia.inria.fr; Sat, 29 Sep 2001 00:46:38 -0400
Received: from www19.w3.org (www19.w3.org [18.29.0.19])
	by tux.w3.org (8.9.3/8.9.3) with ESMTP id AAA17491
	for <rigo@w3.org>; Sat, 29 Sep 2001 00:46:37 -0400
Received: by www19.w3.org (8.9.0/8.9.0) id AAA22749
	for rigo@w3.org; Sat, 29 Sep 2001 00:46:36 -0400 (EDT)
Date: Sat, 29 Sep 2001 00:46:36 -0400 (EDT)
X-Envelope-From: www-p3p-policy-request@tux.w3.org  Sat Sep 29 00:46:23 2001
Received: from tux.w3.org (tux.w3.org [18.29.0.27])
	by www19.w3.org (8.9.0/8.9.0) with ESMTP id AAA22729
	for <www-p3p-policy@www19.w3.org>; Sat, 29 Sep 2001 00:46:23 -0400 (EDT)
Received: from hawk.mail.pas.earthlink.net (hawk.mail.pas.earthlink.net [207.217.120.22])
	by tux.w3.org (8.9.3/8.9.3) with ESMTP id AAA17488
	for <www-p3p-policy@w3.org>; Sat, 29 Sep 2001 00:46:22 -0400
From: jesso2000@earthlink.net
Received: from patrick.earthlink.net (dhcp035-40-151-24.wl02-c3.cpe.charter-ne.com [24.151.40.35])
	by hawk.mail.pas.earthlink.net (EL-8_9_3_3/8.9.3) with ESMTP id VAA03682
	for <www-p3p-policy@w3.org>; Fri, 28 Sep 2001 21:46:20 -0700 (PDT)
Message-Id: <5.1.0.14.2.20010929004421.00a75980@mail.earthlink.net>
X-Sender: jesso2000@mail.earthlink.net
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Old-Date: Sat, 29 Sep 2001 00:46:20 -0400
To: www-p3p-policy@w3.org
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
X-Diagnostic: Not on the accept list
Subject: [Moderator Action] IE 6 and P3P
X-Diagnostic: Mail coming from a daemon, ignored
X-Envelope-To: www-p3p-policy
Resent-From: rigo@localhost
Resent-Date: Mon, 1 Oct 2001 16:11:09 +0200
Resent-To: www-p3p-policy@w3.org

If I understand this correctly, IE 6 requires a site to present a compact
policy ... and from what I can tell the only way to do this is with HTTP
headers. So basically in a nutshell, in order to support IE 6 does one
absolutely have to provide the company policy in the headers of all
requests or is there some other way? We only have a handful of
pages on our site so we were going to simply link to the policy.xml
but now it seems that we have to modify our Apache and send the
correct P3P header that way ... can someone shed some light?

Received on Monday, 1 October 2001 16:59:32 UTC