Re: Upgrading to TLS Within HTTP
Tim Dierks <[email protected]> Mon, 16 Mar 1998 11:49:12 -0800
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <v0311073db1333146d402@[157.22.240.64]> |
At 2:13 AM -0800 3/16/98, Rohit Khare wrote: >Upgrading to TLS Within HTTP > > Rohit Khare, UC Irvine, March 15, 1998 Thanks for this detailed note. I have some questions. (Perhaps we could narrow this down to a smaller number of lists, as well.) - Upgrade is a "hop-by-hop" header. How do you propose to acheive end-to-end security in the presence of caches or proxies? - It seems to me that a straightforward implementation of this would expose the request with the Upgrade: field in it; this request would not be protected by encryption or authentication. Do you have suggestions on how to avoid this problem? Tim Dierks - [email protected] - www.consensus.com Director of Engineering - Consensus Development Developer of SSL Plus: SSL 3.0 Integration Suite