ioggstream / draft-polli-resource-digests-http

THIS REPO WAS MOVED TO https://github.com/httpwg/http-extensions/
https://httpwg.org/http-extensions/draft-ietf-httpbis-digest-headers.html
Other
0 stars 1 forks source link

signing relevant representation metadata is mandatory #37

Open ioggstream opened 5 years ago

ioggstream commented 5 years ago

This PR

States that:

ioggstream commented 5 years ago

@jyasskin maybe related to https://github.com/WICG/webpackage/blame/master/draft-yasskin-http-origin-signed-responses.md#L352

LPardue commented 5 years ago

An alternative way of fixing this is to state the problem in more generic terms. For example, all resource metadata is open to tampering; any methods that attempt to address tampering of the digest header MUST also consider mandatory elements that compose Digest: Content-Type and Content-Encoding.

ioggstream commented 5 years ago

While we could provide those informations in a BCP (eg. like it was done in https://tools.ietf.org/html/rfc6819) I think that it could have sense to provide them here.

Thinking twice, I don't know if the Security Consideration can contain "MUST" & co.

Still imho we should state clearly that:

Let's see how other specs address this kind of issues.