Re: removing keygen from HTML
Nathan Rixham <[email protected]> Wed, 1 Jun 2016 10:30:39 +0100
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CANiy74ybuk8+zVYJGxd-XPaxbJN-H46m3OTJ_de3fvY7BYxwmQ@mail.gmail.com> |
--001a113ff18286dddd053434244c Content-Type: text/plain; charset=UTF-8 How to do auth on web? Honest and serious question. WWW-Authenticate and Authorization provide basic (lol) and digest (mitm), so can't use them. Alternative? Public key authentication (usually implemented with a HTTPS / SSL client certificate) ... sounds good. How to request, provide, or manage/select a client certificate with browser? nothing specified or implemented, maybe use keygen to request? (deprecated in live browsers), maybe provide a certificate with application/x-x509-user-cert (deprecated in live browsers), manage/select? (nothing specified) keygen is specified and was implemented terribly, but where's the alternative. How to do auth on web? A question I certainly can't answer, can anybody here? On Mon, May 30, 2016 at 10:40 AM, Chaals McCathie Nevile < [email protected]> wrote: > Hi folks, > > there is an open issue [1] and open call for consensus [2] to remove > keygen from HTML. Since the TAG, or its members, appear to have opinions > about our spec, we'd be grateful to hear them. > > cheers > > Chaals > > [1] https://github.com/w3c/html/issues/43 > [2] http://www.w3.org/mid/[email protected] > > -- > Charles McCathie Nevile - web standards - CTO Office, Yandex > [email protected] - - - Find more at http://yandex.com > > --001a113ff18286dddd053434244c Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">How to do auth on web?<div><br></div><div>Honest and serio= us question.</div><div><br></div><div>WWW-Authenticate and Authorization pr= ovide basic (lol) and digest (mitm), so can't use them.</div><div><br><= /div><div>Alternative? Public key authentication (usually implemented with = a HTTPS / SSL client certificate) =C2=A0... sounds good.</div><div><br></di= v><div>How to request, provide, or manage/select a client certificate with = browser? nothing specified or implemented, maybe use keygen to request? (de= precated in live browsers), maybe provide a certificate with application/x-= x509-user-cert (deprecated in live browsers), manage/select? (nothing speci= fied)</div><div><br></div><div>keygen is specified and was implemented terr= ibly, but where's the alternative.</div><div><br></div><div>How to do a= uth on web? A question I certainly can't answer, can anybody here?<br><= /div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Mon= , May 30, 2016 at 10:40 AM, Chaals McCathie Nevile <span dir=3D"ltr"><<a= href=3D"mailto:[email protected]" target=3D"_blank">chaals@yandex-team= .ru</a>></span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"mar= gin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi folks,<br> <br> there is an open issue [1] and open call for consensus [2] to remove keygen= from HTML. Since the TAG, or its members, appear to have opinions about ou= r spec, we'd be grateful to hear them.<br> <br> cheers<br> <br> Chaals<br> <br> [1] <a href=3D"https://github.com/w3c/html/issues/43" rel=3D"noreferrer" ta= rget=3D"_blank">https://github.com/w3c/html/issues/43</a><br> [2] <a href=3D"http://www.w3.org/mid/[email protected]" rel= =3D"noreferrer" target=3D"_blank">http://www.w3.org/mid/op.yhs220oos7agh9@w= idsith.local</a><span class=3D"HOEnZb"><font color=3D"#888888"><br> <br> -- <br> Charles McCathie Nevile - web standards - CTO Office, Yandex<br> =C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank">chaals@yan= dex-team.ru</a> - - - Find more at <a href=3D"http://yandex.com" rel=3D"nor= eferrer" target=3D"_blank">http://yandex.com</a><br> <br> </font></span></blockquote></div><br></div> --001a113ff18286dddd053434244c--