Re: HTTP/TLS over a separate port draft
Tom Weinstein <[email protected]> Mon, 09 Feb 1998 14:58:24 -0800
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Organization | Netscape Communications, Inc. |
| Message-ID | <[email protected]> |
David Brownell wrote: > > But for some appropriate usages of the term, HTTP(S) isn't the > application protocol -- it's just a request/response protocol with a > fair degree of infrastructure to dance through firewalls when that's > needed. In this case I'd say "web browsing" is the application, and > the role of HTTPS is to be application infrastructure. > > The role of the PKI here is just to authenticate. The application (web > browser sometimes, but not always) needs to support some kind of > authorization policy. I'd be happy adopting a policy that for "host > oriented services" the DNS name check SHOULD be the norm, particularly > if other services adopted that policy. (LDAP/TLS, SMTP/TLS, etc.) > > Of course, my "personal" web server should probably have my own name > there, not the name currently assigned by my ISP. Here's my reasoning, please correct me if I'm wrong. In all cases, use of HTTP involves referencing a URL. Since a hostname is part of that URL, I would say that the hostname should be verified. In any case, there's a wider problem with authenticating servers that should be addressed in any implementation, and the name check is simply a special case. -- What is appropriate for the master is not appropriate| Tom Weinstein for the novice. You must understand Tao before | [email protected] transcending structure. -- The Tao of Programming |