New rev:
https://tools.ietf.org/html/draft-ietf-websec-strict-transport-sec-08


full issue ticket list for strict-transport-sec:
<http://trac.tools.ietf.org/wg/websec/trac/query?status=assigned&status=closed&status=new&status=reopened&component=strict-transport-sec&order=id>

Redline spec diff from previous rev:
https://tools.ietf.org/rfcdiff?difftype=--hwdiff&url2=draft-ietf-websec-strict-transport-sec-08.txt

side-by-side diff from previous rev:
https://tools.ietf.org/rfcdiff?url2=draft-ietf-websec-strict-transport-sec-08.txt


Change Log is below.


=JeffH


==============================================================


Appendix D. Change Log


   [RFCEditor: please remove this section upon publication as an RFC.]

   Changes are grouped by spec revision listed in reverse issuance
   order.

D.1.  For draft-ietf-websec-strict-transport-sec

      Changes from -07 to -08:

      1.  Clarified requirement #4 for STS header field directives in
          Section 6.1, and removed "(which "update" this
          specification)".  Also added explicit "max-age=0" to Section
          6.1.1.  Reworked final sentence in 2nd para of Section 13.
          This addresses issue ticket #45.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/45>

      Changes from -06 to -07:

      1.  Various minor/modest editorial tweaks throughout as I went
          through it pursuing the below issue tickets.  Viewing a visual
          diff against -06 revision recommended.

      2.  fixed some minor editorial issues noted in review by Alexey,
          fixes noted in here: <https://www.ietf.org/mail-archive/web/
          websec/current/msg01163.html>

      3.  Addressed ABNF exposition issues, specifically inclusion of
          quoted-string syntax for directive values.  Fix STS header
          ABNF such that a leading ";" isn't required.  Add example of
          quoted-string-encoded max-age-value.  This addresses (re-
          opened) issue ticket #33.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/33>

      4.  Reworked sections 8.1 through 8.3 to ensure matching algorithm
          and resultant HSTS Policy application is more clear, and that
          it is explicitly stipulated to not muck with attributes of
          superdomain matching Known HSTS Hosts.  This addresses issue
          ticket #37.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/37>

      5.  Added reference to [I-D.ietf-dane-protocol], pared back
          extraneous discussion in section 2.2, and updated discussion
          in 10.2 to accomodate TLSA (nee DANE).  This addresses issue
          ticket #39.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/39>

      6.  Addressed various editorial items from issue ticket #40.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/40>

      7.  Loosened up the language regarding redirecting "http" requests
          to "https" in section 7.2 such that future flavors of
          permanent redirects are accommodated.  This addresses issue
          ticket #43.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/43>

      8.  Reworked the terminology and language in Section 9, in
          particular defining the term "putative domain name string" to
          replace "valid Unicode-encoded string-serialized domain name".
          This addresses issue ticket #44.
          <http://trac.tools.ietf.org/wg/websec/trac/ticket/44>


       Changes from -05 to -06:
                .
                .
                .
                .
---
end

_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to