| < draft-ietf-httpbis-authscheme-registrations-04.txt | draft-ietf-httpbis-authscheme-registrations-05.txt > | |||
|---|---|---|---|---|
| HTTPbis Working Group J. Reschke | HTTPbis Working Group J. Reschke | |||
| Internet-Draft greenbytes | Internet-Draft greenbytes | |||
| Intended status: Informational August 16, 2012 | Intended status: Informational October 13, 2012 | |||
| Expires: February 17, 2013 | Expires: April 16, 2013 | |||
| Initial Hypertext Transfer Protocol (HTTP) | Initial Hypertext Transfer Protocol (HTTP) | |||
| Authentication Scheme Registrations | Authentication Scheme Registrations | |||
| draft-ietf-httpbis-authscheme-registrations-04 | draft-ietf-httpbis-authscheme-registrations-05 | |||
| Abstract | Abstract | |||
| This document registers Hypertext Transfer Protocol (HTTP) | This document registers Hypertext Transfer Protocol (HTTP) | |||
| authentication schemes which have been defined in standards-track | authentication schemes which have been defined in standards-track | |||
| RFCs before the IANA HTTP Authentication Scheme Registry was | RFCs before the IANA HTTP Authentication Scheme Registry was | |||
| established. | established. | |||
| Editorial Note (To be removed by RFC Editor) | Editorial Note (To be removed by RFC Editor) | |||
| Discussion of this draft takes place on the HTTPBIS working group | Discussion of this draft takes place on the HTTPBIS working group | |||
| mailing list (ietf-http-wg@w3.org), which is archived at | mailing list (ietf-http-wg@w3.org), which is archived at | |||
| <http://lists.w3.org/Archives/Public/ietf-http-wg/>. | <http://lists.w3.org/Archives/Public/ietf-http-wg/>. | |||
| The current issues list is at <http://trac.tools.ietf.org/wg/httpbis/ | The current issues list is at <http://trac.tools.ietf.org/wg/httpbis/ | |||
| trac/query?component=authscheme-registrations> and related documents | trac/query?component=authscheme-registrations> and related documents | |||
| (including fancy diffs) can be found at | (including fancy diffs) can be found at | |||
| <http://tools.ietf.org/wg/httpbis/>. | <http://tools.ietf.org/wg/httpbis/>. | |||
| The changes in this draft are summarized in Appendix B.4. | The changes in this draft are summarized in Appendix B.5. | |||
| Status of This Memo | Status of This Memo | |||
| This Internet-Draft is submitted in full conformance with the | This Internet-Draft is submitted in full conformance with the | |||
| provisions of BCP 78 and BCP 79. | provisions of BCP 78 and BCP 79. | |||
| Internet-Drafts are working documents of the Internet Engineering | Internet-Drafts are working documents of the Internet Engineering | |||
| Task Force (IETF). Note that other groups may also distribute | Task Force (IETF). Note that other groups may also distribute | |||
| working documents as Internet-Drafts. The list of current Internet- | working documents as Internet-Drafts. The list of current Internet- | |||
| Drafts is at http://datatracker.ietf.org/drafts/current/. | Drafts is at http://datatracker.ietf.org/drafts/current/. | |||
| Internet-Drafts are draft documents valid for a maximum of six months | Internet-Drafts are draft documents valid for a maximum of six months | |||
| and may be updated, replaced, or obsoleted by other documents at any | and may be updated, replaced, or obsoleted by other documents at any | |||
| time. It is inappropriate to use Internet-Drafts as reference | time. It is inappropriate to use Internet-Drafts as reference | |||
| material or to cite them other than as "work in progress." | material or to cite them other than as "work in progress." | |||
| This Internet-Draft will expire on February 17, 2013. | This Internet-Draft will expire on April 16, 2013. | |||
| Copyright Notice | Copyright Notice | |||
| Copyright (c) 2012 IETF Trust and the persons identified as the | Copyright (c) 2012 IETF Trust and the persons identified as the | |||
| document authors. All rights reserved. | document authors. All rights reserved. | |||
| This document is subject to BCP 78 and the IETF Trust's Legal | This document is subject to BCP 78 and the IETF Trust's Legal | |||
| Provisions Relating to IETF Documents | Provisions Relating to IETF Documents | |||
| (http://trustee.ietf.org/license-info) in effect on the date of | (http://trustee.ietf.org/license-info) in effect on the date of | |||
| publication of this document. Please review these documents | publication of this document. Please review these documents | |||
| carefully, as they describe your rights and restrictions with respect | carefully, as they describe your rights and restrictions with respect | |||
| skipping to change at page 2, line 23 | skipping to change at page 2, line 23 | |||
| include Simplified BSD License text as described in Section 4.e of | include Simplified BSD License text as described in Section 4.e of | |||
| the Trust Legal Provisions and are provided without warranty as | the Trust Legal Provisions and are provided without warranty as | |||
| described in the Simplified BSD License. | described in the Simplified BSD License. | |||
| Table of Contents | Table of Contents | |||
| 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 3 | 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . . 3 | |||
| 2. Security Considerations . . . . . . . . . . . . . . . . . . . . 3 | 2. Security Considerations . . . . . . . . . . . . . . . . . . . . 3 | |||
| 3. IANA Considerations . . . . . . . . . . . . . . . . . . . . . . 3 | 3. IANA Considerations . . . . . . . . . . . . . . . . . . . . . . 3 | |||
| 4. Normative References . . . . . . . . . . . . . . . . . . . . . 3 | 4. Normative References . . . . . . . . . . . . . . . . . . . . . 3 | |||
| Appendix A. Initial Registry Contents . . . . . . . . . . . . . . 3 | Appendix A. Initial Registry Contents . . . . . . . . . . . . . . 4 | |||
| Appendix B. Change Log (to be removed by RFC Editor before | Appendix B. Change Log (to be removed by RFC Editor before | |||
| publication) . . . . . . . . . . . . . . . . . . . . . 4 | publication) . . . . . . . . . . . . . . . . . . . . . 4 | |||
| B.1. Since draft-ietf-httpbis-authscheme-registrations-00 . . . 4 | B.1. Since draft-ietf-httpbis-authscheme-registrations-00 . . . 4 | |||
| B.2. Since draft-ietf-httpbis-authscheme-registrations-01 . . . 4 | B.2. Since draft-ietf-httpbis-authscheme-registrations-01 . . . 4 | |||
| B.3. Since draft-ietf-httpbis-authscheme-registrations-02 . . . 4 | B.3. Since draft-ietf-httpbis-authscheme-registrations-02 . . . 4 | |||
| B.4. Since draft-ietf-httpbis-authscheme-registrations-03 . . . 4 | B.4. Since draft-ietf-httpbis-authscheme-registrations-03 . . . 4 | |||
| B.5. Since draft-ietf-httpbis-authscheme-registrations-04 . . . 5 | ||||
| 1. Introduction | 1. Introduction | |||
| This document registers Hypertext Transfer Protocol (HTTP) | This document registers Hypertext Transfer Protocol (HTTP) | |||
| authentication schemes which have been defined in standards-track | authentication schemes which have been defined in standards-track | |||
| RFCs before the IANA HTTP Authentication Scheme Registry was | RFCs before the IANA HTTP Authentication Scheme Registry was | |||
| established. | established. | |||
| 2. Security Considerations | 2. Security Considerations | |||
| skipping to change at page 3, line 37 | skipping to change at page 3, line 37 | |||
| Hostetler, J., Lawrence, S., Leach, P., | Hostetler, J., Lawrence, S., Leach, P., | |||
| Luotonen, A., and L. Stewart, "HTTP | Luotonen, A., and L. Stewart, "HTTP | |||
| Authentication: Basic and Digest Access | Authentication: Basic and Digest Access | |||
| Authentication", RFC 2617, June 1999. | Authentication", RFC 2617, June 1999. | |||
| [RFC4559] Jaganathan, K., Zhu, L., and J. Brezak, | [RFC4559] Jaganathan, K., Zhu, L., and J. Brezak, | |||
| "SPNEGO-based Kerberos and NTLM HTTP | "SPNEGO-based Kerberos and NTLM HTTP | |||
| Authentication in Microsoft Windows", | Authentication in Microsoft Windows", | |||
| RFC 4559, June 2006. | RFC 4559, June 2006. | |||
| [draft-ietf-httpbis-p7-auth] Fielding, R., Ed., Lafon, Y., Ed., and | [RFC5849] Hammer-Lahav, E., "The OAuth 1.0 | |||
| J. Reschke, Ed., "HTTP/1.1, part 7: | Protocol", RFC 5849, April 2010. | |||
| Authentication", | ||||
| draft-ietf-httpbis-p7-auth-20 (work in | [RFC6750] Jones, M. and D. Hardt, "The OAuth 2.0 | |||
| progress), July 2012. | Authorization Framework: Bearer Token | |||
| Usage", RFC 6750, October 2012. | ||||
| [draft-ietf-httpbis-p7-auth] Fielding, R., Ed. and J. Reschke, Ed., | ||||
| "Hypertext Transfer Protocol | ||||
| (HTTP/1.1): Authentication", | ||||
| draft-ietf-httpbis-p7-auth-21 (work in | ||||
| progress), October 2012. | ||||
| Appendix A. Initial Registry Contents | Appendix A. Initial Registry Contents | |||
| +----------------+------------+-------------------------------------+ | +----------------+------------+-------------------------------------+ | |||
| | Authentication | Reference | Notes | | | Authentication | Reference | Notes | | |||
| | Scheme Name | | | | | Scheme Name | | | | |||
| +----------------+------------+-------------------------------------+ | +----------------+------------+-------------------------------------+ | |||
| | Basic | [RFC2617], | | | | Basic | [RFC2617], | | | |||
| | | Section 2 | | | | | Section 2 | | | |||
| | Bearer | [RFC6750] | | | ||||
| | Digest | [RFC2617], | | | | Digest | [RFC2617], | | | |||
| | | Section 3 | | | | | Section 3 | | | |||
| | Negotiate | [RFC4559], | This authentication scheme violates | | | Negotiate | [RFC4559], | This authentication scheme violates | | |||
| | | Section 3 | both HTTP semantics (being | | | | Section 3 | both HTTP semantics (being | | |||
| | | | connection-oriented) and syntax | | | | | connection-oriented) and syntax | | |||
| | | | (use of syntax incompatible with | | | | | (use of syntax incompatible with | | |||
| | | | the WWW-Authenticate and | | | | | the WWW-Authenticate and | | |||
| | | | Authorization header field syntax). | | | | | Authorization header field syntax). | | |||
| | OAuth | [RFC5849], | | | ||||
| | | Section | | | ||||
| | | 3.5.1 | | | ||||
| +----------------+------------+-------------------------------------+ | +----------------+------------+-------------------------------------+ | |||
| Appendix B. Change Log (to be removed by RFC Editor before publication) | Appendix B. Change Log (to be removed by RFC Editor before publication) | |||
| B.1. Since draft-ietf-httpbis-authscheme-registrations-00 | B.1. Since draft-ietf-httpbis-authscheme-registrations-00 | |||
| Update draft-ietf-httpbis-p7-auth reference. | Update draft-ietf-httpbis-p7-auth reference. | |||
| B.2. Since draft-ietf-httpbis-authscheme-registrations-01 | B.2. Since draft-ietf-httpbis-authscheme-registrations-01 | |||
| skipping to change at page 4, line 35 | skipping to change at page 5, line 5 | |||
| reserve 'negotiate' as auth scheme name" | reserve 'negotiate' as auth scheme name" | |||
| B.3. Since draft-ietf-httpbis-authscheme-registrations-02 | B.3. Since draft-ietf-httpbis-authscheme-registrations-02 | |||
| Update draft-ietf-httpbis-p7-auth reference. | Update draft-ietf-httpbis-p7-auth reference. | |||
| B.4. Since draft-ietf-httpbis-authscheme-registrations-03 | B.4. Since draft-ietf-httpbis-authscheme-registrations-03 | |||
| Update draft-ietf-httpbis-p7-auth reference. | Update draft-ietf-httpbis-p7-auth reference. | |||
| B.5. Since draft-ietf-httpbis-authscheme-registrations-04 | ||||
| Closed issues: | ||||
| o <http://tools.ietf.org/wg/httpbis/trac/ticket/382>: "add OAuth | ||||
| auth scheme to initial registry contents" | ||||
| Update draft-ietf-httpbis-p7-auth reference. Added OAuth 2.0 Bearer | ||||
| scheme. | ||||
| Author's Address | Author's Address | |||
| Julian F. Reschke | Julian F. Reschke | |||
| greenbytes GmbH | greenbytes GmbH | |||
| Hafenweg 16 | Hafenweg 16 | |||
| Muenster, NW 48155 | Muenster, NW 48155 | |||
| Germany | Germany | |||
| EMail: julian.reschke@greenbytes.de | EMail: julian.reschke@greenbytes.de | |||
| URI: http://greenbytes.de/tech/webdav/ | URI: http://greenbytes.de/tech/webdav/ | |||
| End of changes. 10 change blocks. | ||||
| 11 lines changed or deleted | 33 lines changed or added | |||
This html diff was produced by rfcdiff 1.39p1. The latest version is available from http://tools.ietf.org/tools/rfcdiff/ | ||||