Re: HTML File Validation - do you need it?
Simeon Willbanks <[email protected]> Thu, 05 Feb 2004 12:49:59 -0500
| Newsgroups | gmane.comp.web.p3p.policy |
|---|---|
| Message-ID | <BC47EC77.5702%[email protected]> |
> This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. --B_3158830199_755878 Content-type: text/plain; charset="UTF-8" Content-transfer-encoding: quoted-printable Rigo, Thank you for the explanation. You have been helpful. I now am having a problem with implementation. We have three content servers all pointed to the same domain. We successfully validated a p3p policy on all three content servers, then we validated the p3p policy on th= e domain itself.=20 We also have an ad server in the mix. It runs at port 8080. We placed the same p3p policy on this server and ran the validator. This is the message we received: =20 HTTP headers are P3P compliant . Warning: Multiple P3P headers. P3P:CP=3D"NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT", policyref=3D"/w3c/p3p.xml" P3P:CP=3D"NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT", policyref=3D"/w3c/p3p.xml" It appears the validator is getting double headers from our web server and ad server. When the p3p policy is removed from the httpd.config file on th= e ad server, the validator does not see a p3p policy at all. We get this error: Step 2: HTTP Protocol Validation (HTTP headers ) HTTP headers have no P3P: header. When the double headers were in place, I loaded a few pages on our site. I= E blocked all cookies from the ad server, even though the validator said the url to the ad server was valid. Could that be because of the presence of 2 compact policies? Could this be happening because of the port number? How could we make only one policy appear on the ad server? My IE settings were at, =E2=80=9Cblocks cookies that do not have a compact privacy policy." Thanks for the help, Simeon =20 On 2/5/04 6:50 AM, "Rigo Wenning" <[email protected]> wrote: >=20 > Dear Simeon,=20 >=20 >> Thanks to the archives on this list, my p3p compact policy and p3p.xml a= re >> validating. Thanks! I realize you need to have both of these in workin= g >> order to be inline with Microsoft. >=20 > Good to hear! >=20 >>=20 >> My question is this, do you need to have the "HTML File Validation" set = in >> order to have the policy work? My understanding is that you don=C2=B9t. Th= e W3 >> only requires one of the three to be valid, and MS likes you to have the >> compact policy and policy reference in place. Am I correct? This will = also >> save a lot of time because, we will not have change each page on our sit= e, >> just make the modifications in apache. >=20 > I had that issue with another implementer already. Depending on your > web-site, it is preferred to start with the well-known-location. The > link-tag is only there for sites like geocities that have thousands of > users with different setups. It would be overkill for them to maintain a > single policy reference file. >=20 > But in your case, as you already said, this is the opposite. If you see > that P3P implementations don't support the well-known-location or the > header-mechanism, please report that here. >=20 > Best,=20 --B_3158830199_755878 Content-type: text/html; charset="UTF-8" Content-transfer-encoding: quoted-printable <HTML> <HEAD> <TITLE>Re: HTML File Validation - do you need it?</TITLE> </HEAD> <BODY> <FONT FACE=3D"Verdana">Rigo,<BR> <BR> Thank you for the explanation. You have been helpful. <BR> <BR> I now am having a problem with implementation. We have three content = servers all pointed to the same domain. We successfully validated a p3= p policy on all three content servers, then we validated the p3p policy on t= he domain itself. <BR> <BR> We also have an ad server in the mix. It runs at port 8080. We = placed the same p3p policy on this server and ran the validator. This = is the message we received: <BR> <BR> HTTP headers are P3P compliant .<BR> Warning: Multiple P3P headers. <BR> P3P:CP=3D"NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT", pol= icyref=3D"/w3c/p3p.xml"<BR> P3P:CP=3D"NOI CURa ADMa DEVa TAIa OUR BUS IND UNI COM NAV INT", pol= icyref=3D"/w3c/p3p.xml" <BR> <BR> It appears the validator is getting double headers from our web server and = ad server. When the p3p policy is removed from the httpd.config file o= n the ad server, the validator does not see a p3p policy at all. We ge= t this error:<BR> <BR> </FONT><FONT FACE=3D"Geneva">Step 2: HTTP Protocol Validation (HTTP headers )= <BR> HTTP headers have no P3P: header. <BR> <BR> When the double headers were in place, I loaded a few pages on our site. &n= bsp;IE blocked all cookies from the ad server, even though the validator sai= d the url to the ad server was valid. Could that be because of the pre= sence of 2 compact policies? Could this be happening because of the po= rt number? How could we make only one policy appear on the ad server? = My IE settings were at, “blocks cookies that do not have a compa= ct privacy policy."<BR> <BR> Thanks for the help,<BR> Simeon <BR> <BR> </FONT><FONT FACE=3D"Verdana"><BR> On 2/5/04 6:50 AM, "Rigo Wenning" <[email protected]> wrote:<BR> <BR> <FONT COLOR=3D"#0000FF">> <BR> </FONT></FONT><FONT COLOR=3D"#0000FF"><FONT FACE=3D"AppleMyungjo">> Dear Sim= eon, <BR> > <BR> </FONT></FONT><FONT FACE=3D"AppleMyungjo"><FONT COLOR=3D"#008000">>> Than= ks to the archives on this list, my p3p compact policy and p3p.xml are<BR> >> validating. Thanks! I realize you need to have both of= these in working<BR> >> order to be inline with Microsoft.<BR> </FONT><FONT COLOR=3D"#0000FF">> <BR> > Good to hear!<BR> > <BR> </FONT><FONT COLOR=3D"#008000">>> <BR> >> My question is this, do you need to have the "HTML File Valid= ation" set in<BR> >> order to have the policy work? My understanding is that you = don¹t. The W3<BR> >> only requires one of the three to be valid, and MS likes you to ha= ve the<BR> >> compact policy and policy reference in place. Am I correct? = This will also<BR> >> save a lot of time because, we will not have change each page on o= ur site,<BR> >> just make the modifications in apache.<BR> </FONT><FONT COLOR=3D"#0000FF">> <BR> > I had that issue with another implementer already. Depending on your<B= R> > web-site, it is preferred to start with the well-known-location. The<B= R> > link-tag is only there for sites like geocities that have thousands of= <BR> > users with different setups. It would be overkill for them to maintain= a<BR> > single policy reference file. <BR> > <BR> > But in your case, as you already said, this is the opposite. If you se= e<BR> > that P3P implementations don't support the well-known-location or the<= BR> > header-mechanism, please report that here.<BR> > <BR> > Best, <BR> </FONT></FONT> </BODY> </HTML> --B_3158830199_755878--