Re: [websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5

2018-03-09 Thread Svensson, Lars
Yoav, Eric, Thanks for your insights. Best, Lars From: Eric Mill [mailto:eric.m...@gsa.gov] Sent: Thursday, March 01, 2018 6:45 PM To: Yoav Nir Cc: Svensson, Lars ; websec@ietf.org Subject: Re: [websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5 Yoav's diagram

Re: [websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5

2018-03-01 Thread Eric Mill
Yoav's diagram is my understanding as well. On Thu, Mar 1, 2018 at 11:11 AM, Yoav Nir wrote: > This is how I understand it: > > > On 1 Mar 2018, at 13:59, Svensson, Lars wrote: > > When implementing HSTS, my colleagues and I had discussions on how to > correctly interpret §8.3, #5 of RFC 6797 [

Re: [websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5

2018-03-01 Thread Yoav Nir
This is how I understand it: > On 1 Mar 2018, at 13:59, Svensson, Lars wrote: > > When implementing HSTS, my colleagues and I had discussions on how to > correctly interpret §8.3, #5 of RFC 6797 [1]. In our opinion the text is > ambiguous and we hope that you can help us to clarify what is th

[websec] Question regarding RFC 6797: What is the proper reading of §8.3 #5

2018-03-01 Thread Svensson, Lars
When implementing HSTS, my colleagues and I had discussions on how to correctly interpret §8.3, #5 of RFC 6797 [1]. In our opinion the text is ambiguous and we hope that you can help us to clarify what is the proper reading of that section. In §8.3 #5 the following is stated: [[ If, when perfor