Re: [websec] Review of draft-ietf-websec-strict-transport-sec-06.txt

2012-05-04 Thread Peter Saint-Andre
On 5/4/12 2:47 AM, Alexey Melnikov wrote: On 3 May 2012, at 20:40, Peter Saint-Andre stpe...@stpeter.im wrote: On 5/2/12 1:45 PM, =JeffH wrote: 13. Internationalized Domain Names for Applications (IDNA): Dependency and Migration IDNA2008 obsoletes IDNA2003, but there are

Re: [websec] Review of draft-ietf-websec-strict-transport-sec-06.txt

2012-05-03 Thread Peter Saint-Andre
On 5/2/12 1:45 PM, =JeffH wrote: 13. Internationalized Domain Names for Applications (IDNA): Dependency and Migration IDNA2008 obsoletes IDNA2003, but there are differences between the two specifications, and thus there can be differences in processing (e.g., converting)

Re: [websec] Review of draft-ietf-websec-strict-transport-sec-06.txt

2012-05-02 Thread =JeffH
[ resent with correct Subject: ] Hi Alexey, thanks for the review, apologies for latency. The two directives defined in this specification are described below. The overall requirements for directives are: o The order of appearance of directives is not significant. o All

[websec] Review of draft-ietf-websec-strict-transport-sec-06.txt

2012-04-04 Thread Alexey Melnikov
Hi, Below is my WGLC review of the draft: 6.1. Strict-Transport-Security HTTP Response Header Field The Strict-Transport-Security HTTP response header field (STS header field) indicates to a UA that it MUST enforce the HSTS Policy in regards to the host emitting the response message