-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
" Certificate processing errors should result in a HTTP return code of
403 "Forbidden" along with a body of type "text/plain" and body that
consists of one of the tokens defined in the following list:
failed_authentication The user name and password combination was not
correct.
username_not_available The requested userName for the certificate
was not acceptable.
Node-IDs_not_available The number of Node-IDs requested was not
acceptable.
bad_CSR There was a problem with the CSR.
If the client receives an unknown token in the body, it SHOULD treat
it as a failure for an unknown reasons."
What was the reason for passing the username and password as form parameter
instead of using an Authorization headers? Using Authorization would have
permit to return 401 for a failed authorization and would have permit to use
other authentication methods.
Nits:
====
s/along with a body of type "text/plain" and body that consists/along with a
body of type "text/plain" that consists/
s/userName/username/
(and yes, I am well aware that my insistence in sending reviews and nits that
are consistently ignored by the authors fits very well Einstein's definition
of insanity)
- --
Marc Petit-Huguenin
Email: [email protected]
Blog: http://blog.marc.petit-huguenin.org
Profile: http://www.linkedin.com/in/petithug
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBCAAGBQJQBKEcAAoJECnERZXWan7EbMwQAOVTy+2mpCD9dihZjA7y0sN2
mZ38RnxNAE0LIGJySpEBZ6Y+fEBhffYHkyw8JSsmuT2hjTe+ikxXSkGYChC82Rff
a6Ozj8s2Sg3EEvoH0+rxUVlxd4hPq9Cq9Tcb/WRLUjfoZJICz/GU0CjhZdVTLS/z
S7F3k8sFQekAHypD40j0TPKLCHLqMNWtHiCGrM7fD7rQa++0++A7qkETmZxjj5dy
o0ce8K8lnsK4yTvDS5WkanVFROm303YM4qayf9aBKqBfgFnLiE0JwTryZF9GBCDO
nbBKm85eD7sdTay5NPHDyJvcAnYWQ7BGXuzqSsUkXuVTUU7kX3nYQlpzapseSzkv
bh0JJUfLta6xey9vpOO2HCmU1MfRd1qOQ6l8vLK/f269e3w09JRu48batIWT7xe1
RjMqI89HmB4l+PFDE/pxhBNr+0KA40C1RTNiKaPv+SUhI9ETOCeiwfCZ2bgpW4hH
Gej5dRlKngTxLH+pnV6psszuO/+LQbYP2dEwT98J0SzGe42nlXa0kJ3M9TOuQLss
4sjObYDg2LGcxLFG8uf9hUZAkREmd8uMUxI6Kpyh3q1yXeK3BVBpUb7jXbtQKMVO
bIwX6ByE2uI3TNSdYrdUr0qztGcAHELNOjJeJXQJi1bRHtRos3EurFPFiy2DFNaI
/bjdHptLo8P+6TSk8JH1
=efuQ
-----END PGP SIGNATURE-----
_______________________________________________
P2PSIP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/p2psip