Re: removing keygen from HTML

Nathan Rixham <[email protected]> Wed, 1 Jun 2016 10:30:39 +0100
Newsgroups gmane.org.w3c.tag
Message-ID <CANiy74ybuk8+zVYJGxd-XPaxbJN-H46m3OTJ_de3fvY7BYxwmQ@mail.gmail.com>
--001a113ff18286dddd053434244c
Content-Type: text/plain; charset=UTF-8

How to do auth on web?

Honest and serious question.

WWW-Authenticate and Authorization provide basic (lol) and digest (mitm),
so can't use them.

Alternative? Public key authentication (usually implemented with a HTTPS /
SSL client certificate)  ... sounds good.

How to request, provide, or manage/select a client certificate with
browser? nothing specified or implemented, maybe use keygen to request?
(deprecated in live browsers), maybe provide a certificate with
application/x-x509-user-cert (deprecated in live browsers), manage/select?
(nothing specified)

keygen is specified and was implemented terribly, but where's the
alternative.

How to do auth on web? A question I certainly can't answer, can anybody
here?

On Mon, May 30, 2016 at 10:40 AM, Chaals McCathie Nevile <
[email protected]> wrote:

> Hi folks,
>
> there is an open issue [1] and open call for consensus [2] to remove
> keygen from HTML. Since the TAG, or its members, appear to have opinions
> about our spec, we'd be grateful to hear them.
>
> cheers
>
> Chaals
>
> [1] https://github.com/w3c/html/issues/43
> [2] http://www.w3.org/mid/[email protected]
>
> --
> Charles McCathie Nevile - web standards - CTO Office, Yandex
>  [email protected] - - - Find more at http://yandex.com
>
>

--001a113ff18286dddd053434244c
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">How to do auth on web?<div><br></div><div>Honest and serio=
us question.</div><div><br></div><div>WWW-Authenticate and Authorization pr=
ovide basic (lol) and digest (mitm), so can&#39;t use them.</div><div><br><=
/div><div>Alternative? Public key authentication (usually implemented with =
a HTTPS / SSL client certificate) =C2=A0... sounds good.</div><div><br></di=
v><div>How to request, provide, or manage/select a client certificate with =
browser? nothing specified or implemented, maybe use keygen to request? (de=
precated in live browsers), maybe provide a certificate with application/x-=
x509-user-cert (deprecated in live browsers), manage/select? (nothing speci=
fied)</div><div><br></div><div>keygen is specified and was implemented terr=
ibly, but where&#39;s the alternative.</div><div><br></div><div>How to do a=
uth on web? A question I certainly can&#39;t answer, can anybody here?<br><=
/div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Mon=
, May 30, 2016 at 10:40 AM, Chaals McCathie Nevile <span dir=3D"ltr">&lt;<a=
 href=3D"mailto:[email protected]" target=3D"_blank">chaals@yandex-team=
.ru</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi folks,<br>
<br>
there is an open issue [1] and open call for consensus [2] to remove keygen=
 from HTML. Since the TAG, or its members, appear to have opinions about ou=
r spec, we&#39;d be grateful to hear them.<br>
<br>
cheers<br>
<br>
Chaals<br>
<br>
[1] <a href=3D"https://github.com/w3c/html/issues/43" rel=3D"noreferrer" ta=
rget=3D"_blank">https://github.com/w3c/html/issues/43</a><br>
[2] <a href=3D"http://www.w3.org/mid/[email protected]" rel=
=3D"noreferrer" target=3D"_blank">http://www.w3.org/mid/op.yhs220oos7agh9@w=
idsith.local</a><span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
-- <br>
Charles McCathie Nevile - web standards - CTO Office, Yandex<br>
=C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank">chaals@yan=
dex-team.ru</a> - - - Find more at <a href=3D"http://yandex.com" rel=3D"nor=
eferrer" target=3D"_blank">http://yandex.com</a><br>
<br>
</font></span></blockquote></div><br></div>

--001a113ff18286dddd053434244c--