Re: [http-auth] Last Call: <draft-ietf-httpauth-basicauth-update-05.txt> (The 'Basic' HTTP Authentication Scheme) to Proposed Standard

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 2015-02-10 20:57, Tony Hansen wrote:

On 2/6/15 1:43 AM, Julian Reschke wrote:
On 2015-02-05 23:49, Bjoern Hoehrmann wrote:
* The IESG wrote:
Abstract

   This document defines the "Basic" Hypertext Transfer Protocol (HTTP)
   Authentication Scheme, which transmits credentials as
userid/password
   pairs, obfuscated by the use of Base64 encoding.

I do not think the use of Base64 is intended as obfuscation and it seems
misleading to me to describe it as such. (The Introduction has the same
problem).

I think it was.

I thought the primary reason was so that the credentials would be able
to contain arbitrary characters, potentially not otherwise representable
within the surrounding protocol. It's an encoding scheme, not an
obfuscation scheme.

How is the intent actually relevant here?

Best regards, Julian











[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]