Re: [comment] P3P 1.1 Well Known Location

Rigo Wenning <[email protected]> Fri, 31 Mar 2006 10:18:31 +0200
Newsgroups gmane.comp.web.p3p.devel
Organization W3C
Message-ID <200603311018.40235@rigo>
--nextPart1503893.WYV0xAtvfm
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Karl,=20

this is a feature of P3P 1.0 and was not touched by the 1.1 works. Dan=20
Connolly complained for the P3P 1.0 version of it. It was explained to him=
=20
and to others that a P3P user agent will very only take into account files=
=20
that carry the P3P namespace. So if a site has already used up /w3c/p3p.xml=
=20
by some other format, it can't use the well-known location anymore, but has=
=20
to use the http-headers. This was accepted in P3P 1.0.

It has to be noted nevertheless that over 90% of the sites using P3P use th=
e=20
well-known location. So as this touches on P3P 1.0, was cleared in the=20
process of the P3P 1.0 Recommendation. As you are not part of the P3P Worki=
ng=20
Group, I don't see where the _formal_ objection should come from, but feel=
=20
free to write down a minority view that can be attached to the Last Call=20
report.=20

Note perhaps that I would have expected rather a comment on the P3P generic=
=20
attribute from you. I would be more interested in your remarks on this new=
=20
feature that allows to address privacy metadata in any XML dialect.=20

Best,=20

Rigo Wenning=20
Privacy Activity Lead

Am Friday 31 March 2006 05:17, sprach Karl Dubost:
> [[[
> 2.2.1 Well-Known Location
>
> Web sites using P3P MAY (and, are strongly encouraged to) place a
> policy reference file in a "well-known" location. To do this, a
> policy reference file would be made available on the site at the
> path /w3c/p3p.xml
> ]]]
>
> -- The Platform for Privacy Preferences 1.1 (P3P1.1) Specification
> http://www.w3.org/TR/2006/WD-P3P11-20060210/#Well_Known_Location
> Mon, 13 Feb 2006 15:51:33 GMT
>
> Any specification MUST not encourage to squat the URI space. To be
> reviewed with the TAG.
> Formal Objection.

--nextPart1503893.WYV0xAtvfm
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQBELOXgCRlGO2Cxp/0RAjM+AJsGgj48epW7BLBIMoGYmNS+sbF3sACfccgm
DPOQTKXy5PGfvufAuXONudg=
=yXu2
-----END PGP SIGNATURE-----

--nextPart1503893.WYV0xAtvfm--