Re: Autoconfig ISP fetch security review

2009-11-06 Thread Eran Hammer-Lahav
On Nov 5, 8:58 pm, Bil Corry b...@corry.biz wrote:
 Gervase Markham wrote on 11/5/2009 2:00 AM:

  On 05/11/09 04:58, Bil Corry wrote:
  You may want to consider registering a /.well-known/ path for this,
  which it seems perfectly suited for:

         http://tools.ietf.org/html/draft-nottingham-site-meta

  That draft seems like a let's make the best of it way of dealing with
  an unfortunate inevitability :-|.

 For anyone who has suggestions or recommendations to improve it, it's being 
 discussed on IETF apps-discuss:

        https://www.ietf.org/mailman/listinfo/apps-discuss

 - Bil

You might also want to take a look at the related host-meta proposal
[1] as well as the WebFinger project. Host-meta provides a well-known
location document for protocols with simple metadata or policy
requirements and WebFinger defines a way to find profile and
configuration information about accounts (which in the case of email
providers is also about email addresses).

EHL

[1] http://tools.ietf.org/html/draft-hammer-hostmeta
[2] http://code.google.com/p/webfinger/
___
dev-security mailing list
dev-security@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security


Re: Autoconfig ISP fetch security review

2009-11-05 Thread Bil Corry
Gervase Markham wrote on 11/5/2009 2:00 AM: 
 On 05/11/09 04:58, Bil Corry wrote:
 You may want to consider registering a /.well-known/ path for this,
 which it seems perfectly suited for:

  http://tools.ietf.org/html/draft-nottingham-site-meta
 
 That draft seems like a let's make the best of it way of dealing with
 an unfortunate inevitability :-|.

For anyone who has suggestions or recommendations to improve it, it's being 
discussed on IETF apps-discuss:

https://www.ietf.org/mailman/listinfo/apps-discuss


- Bil

___
dev-security mailing list
dev-security@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security