Re: Upgrading to TLS Within HTTP

Tim Dierks <[email protected]> Mon, 16 Mar 1998 11:49:12 -0800
Newsgroups gmane.ietf.apps-tls
Message-ID <v0311073db1333146d402@[157.22.240.64]>
At 2:13 AM -0800 3/16/98, Rohit Khare wrote:
>Upgrading to TLS Within HTTP
>
>   Rohit Khare, UC Irvine, March 15, 1998

Thanks for this detailed note. I have some questions. (Perhaps we could
narrow this down to a smaller number of lists, as well.)

 - Upgrade is a "hop-by-hop" header. How do you propose to acheive
end-to-end security in the presence of caches or proxies?

 - It seems to me that a straightforward implementation of this would
expose the request with the Upgrade: field in it; this request would not be
protected by encryption or authentication. Do you have suggestions on how
to avoid this problem?

Tim Dierks - [email protected] - www.consensus.com
  Director of Engineering - Consensus Development
  Developer of SSL Plus: SSL 3.0 Integration Suite