I'd also question the purpose of TLS (ie, HTTPS vs HTTP) in this
context.  All the data are signed, there's no confidentiality or
access control reuirement as far as I know, and the manifest design
was specifically intended to remove the need for channel security.
The draft doesn't contain any real analysis of what threats the
protocol needs to defend against or why TLS is the right solution.
_______________________________________________
sidr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to