Re: HTTP/TLS over a separate port draft

Tom Weinstein <[email protected]> Mon, 09 Feb 1998 14:58:24 -0800
Newsgroups gmane.ietf.apps-tls
Organization Netscape Communications, Inc.
Message-ID <[email protected]>
David Brownell wrote:
> 
> But for some appropriate usages of the term, HTTP(S) isn't the
> application protocol -- it's just a request/response protocol with a
> fair degree of infrastructure to dance through firewalls when that's
> needed.  In this case I'd say "web browsing" is the application, and
> the role of HTTPS is to be application infrastructure.
> 
> The role of the PKI here is just to authenticate.  The application (web
> browser sometimes, but not always) needs to support some kind of
> authorization policy.  I'd be happy adopting a policy that for "host
> oriented services" the DNS name check SHOULD be the norm, particularly
> if other services adopted that policy.  (LDAP/TLS, SMTP/TLS, etc.)
> 
> Of course, my "personal" web server should probably have my own name
> there, not the name currently assigned by my ISP.

Here's my reasoning, please correct me if I'm wrong.  In all cases, use of
HTTP involves referencing a URL.  Since a hostname is part of that URL, I
would say that the hostname should be verified.

In any case, there's a wider problem with authenticating servers that
should be addressed in any implementation, and the name check is simply
a special case.

-- 
What is appropriate for the master is not appropriate| Tom Weinstein
for the novice.  You must understand Tao before      | [email protected]
transcending structure.  -- The Tao of Programming   |