1 |
wakaba |
1.1 |
<?xml version="1.0" encoding="iso-2022-jp"?>
|
2 |
|
|
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
|
3 |
|
|
<html xmlns:h="http://www.w3.org/1999/xhtml" xmlns="http://www.w3.org/1999/xhtml">
|
4 |
|
|
<head profile="http://suika.fam.cx/~wakaba/lang/rfc/translation/html-profile">
|
5 |
|
|
<meta http-equiv="Content-Style-Type" content="text/css"/>
|
6 |
|
|
<title>
|
7 |
|
|
RFC 2659:
|
8 |
|
|
HTML$B$N0BA4@-3HD%(B (Security Extensions For HTML)
|
9 |
|
|
</title>
|
10 |
|
|
<link rel="stylesheet" href="http://suika.fam.cx/~wakaba/lang/rfc/translation/rfc-ja-style.css" type="text/css"/>
|
11 |
|
|
<link rel="alternate" href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2659" hreflang="en" title="RFC 2659"/>
|
12 |
|
|
<link rev="made" href="http://www.rfceditor.org/" title="RFC Editor"/>
|
13 |
|
|
<link rev="translate" href="#rfc-translators-note"/>
|
14 |
|
|
<meta name="author" content="Eric Rescorla, Allan M. Schiffman, "/>
|
15 |
|
|
</head>
|
16 |
|
|
<body>
|
17 |
|
|
<div id="rfc--table">
|
18 |
|
|
<ul id="rfc--table-left">
|
19 |
|
|
<li>Network Working Group</li>
|
20 |
|
|
<li>Request for Comments: 2659</li>
|
21 |
|
|
<li>
|
22 |
|
|
<span class="t-pair">
|
23 |
|
|
<span xml:lang="en" class="t-l-en">Category: Experimental</span>
|
24 |
|
|
</span>
|
25 |
|
|
</li>
|
26 |
|
|
<li>
|
27 |
|
|
<span class="t-pair">
|
28 |
|
|
<span xml:lang="ja" class="t-l-ja">$BJ,N`(B: $B<B83E*(B</span>
|
29 |
|
|
</span>
|
30 |
|
|
</li>
|
31 |
|
|
</ul>
|
32 |
|
|
<ul id="rfc--table-right">
|
33 |
|
|
<li title="Eric Rescorla">E. Rescorla</li>
|
34 |
|
|
<li>RTFM, Inc.</li>
|
35 |
|
|
<li title="Allan M. Schiffman">A. Schiffman</li>
|
36 |
|
|
<li title="SPYRUS/Terisa">Terisa Systems, Inc.</li>
|
37 |
|
|
<li>
|
38 |
|
|
<span class="t-pair">
|
39 |
|
|
<span xml:lang="en" class="t-l-en"> August 1999</span>
|
40 |
|
|
</span>
|
41 |
|
|
</li>
|
42 |
|
|
<li>
|
43 |
|
|
<span class="t-pair">
|
44 |
|
|
<span xml:lang="ja" class="t-l-ja">1999$BG/(B8$B7n(B</span>
|
45 |
|
|
</span>
|
46 |
|
|
</li>
|
47 |
|
|
</ul>
|
48 |
|
|
</div>
|
49 |
|
|
<div class="t-pair t-heading" id="rfc-title">
|
50 |
|
|
<h1 class="rfc-title t-l-en" xml:lang="en">Security Extensions For HTML</h1>
|
51 |
|
|
<h1 class="rfc-title t-l-ja" xml:lang="ja">HTML$B$N0BA4@-3HD%(B</h1>
|
52 |
|
|
</div>
|
53 |
|
|
<div id="rfc-status" class="rfc-section">
|
54 |
|
|
<div class="t-pair">
|
55 |
|
|
<h1 xml:lang="en" class="t-l-en">Status of this Memo</h1>
|
56 |
|
|
<h1 xml:lang="ja" class="t-l-ja">$B$3$N%a%b$N0LCVIU$1(B</h1>
|
57 |
|
|
</div>
|
58 |
|
|
<div class="rfc-t">
|
59 |
|
|
<div class="t-pair">
|
60 |
|
|
<p class="t-l-en" xml:lang="en">
|
61 |
|
|
This memo defines an Experimental Protocol for the Internet community.
|
62 |
|
|
It does not specify an Internet standard of any kind.
|
63 |
|
|
Discussion and suggestions for improvement are requested.
|
64 |
|
|
Distribution of this memo is unlimited.
|
65 |
|
|
</p>
|
66 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
67 |
|
|
$B$3$N%a%b$O!"(B Internet $B<R2q8~$1$N<B83E*%W%m%H%3%k$rDj5A$9$k$b$N$G$9!#$$$+$J$k<oN`$N(B
|
68 |
|
|
Internet $BI8=`$r5,Dj$9$k$b$N$G$b$"$j$^$;$s!#2~NI$N0Y$N5DO@$dDs0F$r5a$a$^$9!#$3$N%a%b$NG[I[$O@)8B$7$^$;$s!#(B
|
69 |
|
|
</p>
|
70 |
|
|
</div>
|
71 |
|
|
</div>
|
72 |
|
|
</div>
|
73 |
|
|
<div id="rfc-copyright-notice" class="rfc-section">
|
74 |
|
|
<div class="t-pair">
|
75 |
|
|
<h1 xml:lang="en" class="t-l-en">Copyright Notice</h1>
|
76 |
|
|
<h1 xml:lang="ja" class="t-l-ja">$BCx:n8"I=<((B</h1>
|
77 |
|
|
</div>
|
78 |
|
|
<div class="t-pair t-hide-no">
|
79 |
|
|
<p class="t-l-en" xml:lang="en">Copyright ©
|
80 |
|
|
<a href="http://www.isoc.org/">The Internet Society</a>
|
81 |
|
|
(1999).
|
82 |
|
|
All Rights Reserved.</p>
|
83 |
|
|
<p class="t-l-ja" xml:lang="ja">$BCx:n8"(B ©
|
84 |
|
|
<a href="http://www.isoc.org/">The Internet Society</a>
|
85 |
|
|
(1999)$B!#A48"J]N1!#(B</p>
|
86 |
|
|
</div>
|
87 |
|
|
</div>
|
88 |
|
|
<div class="rfc-section" id="rfc.abstract">
|
89 |
|
|
<div class="t-pair t-heading">
|
90 |
|
|
<h1 xml:lang="en" class="t-l-en">Abstract</h1>
|
91 |
|
|
<h1 xml:lang="ja" class="t-l-ja">$B35MW(B</h1>
|
92 |
|
|
</div>
|
93 |
|
|
<div class="rfc-t">
|
94 |
|
|
<div class="t-pair">
|
95 |
|
|
<p xml:lang="en" class="t-l-en">
|
96 |
|
|
This memo describes a syntax for embedding S-HTTP negotiation
|
97 |
|
|
parameters in HTML documents. S-HTTP, as described by
|
98 |
|
|
<a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="RFC 2660">RFC 2660</a>, contains the concept of
|
99 |
|
|
negotiation headers which reflect the potential receiver of
|
100 |
|
|
a message's preferences as to which cryptographic enhancements
|
101 |
|
|
should be applied to the message. This document describes a
|
102 |
|
|
syntax for binding these negotiation parameters to HTML anchors.
|
103 |
|
|
</p>
|
104 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
105 |
|
|
$B$3$N%a%b$O!"(B HTML $BJ8=qCf$K(B S-HTTP
|
106 |
|
|
$B@^>W%Q%i%a!<%?!<$rKd$a9~$`9=J8$r@bL@$7$^$9!#(B
|
107 |
|
|
<a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="RFC 2660">RFC 2660</a> $B$G@bL@$5$l$F$$$k(B
|
108 |
|
|
S-HTTP $B$O!"$I$N0E9f3HD%$r%a%C%;!<%8$KE,MQ$9$k$+$N!"%a%C%;!<%8$N@x:_<u?.<T$N9%$_$rH?1G$9$k@^>WF,$N35G0$r4^$s$G$$$^$9!#$3$NJ8=q$O$3$l$i$N@^>W%Q%i%a!<%?!<$r(B
|
109 |
|
|
HTML $BIE$KG{$jIU$1$k9=J8$r@bL@$7$^$9!#(B
|
110 |
|
|
</p>
|
111 |
|
|
</div>
|
112 |
|
|
</div>
|
113 |
|
|
</div>
|
114 |
|
|
|
115 |
|
|
<div class="rfc-section" id="rfc.section.1">
|
116 |
|
|
<div class="t-pair t-heading">
|
117 |
|
|
<h1 xml:lang="en" class="t-l-en">1. Introduction</h1>
|
118 |
|
|
<h1 xml:lang="ja" class="t-l-ja">1.
|
119 |
|
|
$B$O$8$a$K(B</h1>
|
120 |
|
|
</div>
|
121 |
|
|
<ins class="t-note t-l-ja" xml:lang="ja">
|
122 |
|
|
<span class="t-note-title">$BLuCm(B: </span>
|
123 |
|
|
<p class="rfc-t" id="rfc.section.1.p.1">$B86J8$G7gMn!#(B</p>
|
124 |
|
|
</ins>
|
125 |
|
|
</div>
|
126 |
|
|
|
127 |
|
|
<div class="rfc-section" id="rfc.section.2">
|
128 |
|
|
<div class="t-pair t-heading">
|
129 |
|
|
<h1 xml:lang="en" class="t-l-en">2. Anchor Attributes</h1>
|
130 |
|
|
<h1 xml:lang="ja" class="t-l-ja">2.
|
131 |
|
|
$BIEB0@-(B</h1>
|
132 |
|
|
</div>
|
133 |
|
|
<div class="rfc-t" id="rfc.section.2.p.1">
|
134 |
|
|
<div class="t-pair">
|
135 |
|
|
<p xml:lang="en" class="t-l-en">
|
136 |
|
|
We define the following new anchor (and form submission) attributes:
|
137 |
|
|
</p>
|
138 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
139 |
|
|
$B<!$N?7$7$$IE(B ($B$H(B form $BAw?.(B) $BB0@-$rDj5A$7$^$9!#(B
|
140 |
|
|
</p>
|
141 |
|
|
</div>
|
142 |
|
|
|
143 |
|
|
<dl class="rfc-list-hanging">
|
144 |
|
|
<dt id="html-a-dn">
|
145 |
|
|
<a href="#html-a-dn" class="self">DN</a>
|
146 |
|
|
</dt>
|
147 |
|
|
<dd>
|
148 |
|
|
<div class="t-pair">
|
149 |
|
|
<p xml:lang="en" class="t-l-en">
|
150 |
|
|
The distinguished name of the principal for whom the
|
151 |
|
|
request should be encrypted when dereferencing the anchor's url.
|
152 |
|
|
This need not be specified, but failure to do so runs the risk
|
153 |
|
|
that the client will be unable to determine the DN and therefore
|
154 |
|
|
will be unable to encrypt. This should be specified in the form
|
155 |
|
|
of <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:1485" title="RFC 1485">RFC1485</a>,
|
156 |
|
|
using SGML quoting conventions as needed.
|
157 |
|
|
</p>
|
158 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
159 |
|
|
$BIE$N(B url
|
160 |
|
|
$B$r2r;2>H(B (dereference) $B$9$k;~$KMW5a$,0E9f2=$9$k$Y$-BP>]<T$N<1JL$5$l$?L>A0!#(B
|
161 |
|
|
$B$3$l$O;XDj$9$kI,MW$O$"$j$^$;$s$,!"%/%i%$%"%s%H$,(B DN
|
162 |
|
|
$B$r7hDj=PMh$:!"$R$$$F$O0E9f2=$b=PMh$J$/$J$k4m81$rKA$9$3$H$K$J$j$^$9!#(B
|
163 |
|
|
<a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:1485" title="RFC 1485">RFC 1485</a>
|
164 |
|
|
$B$N7A<0$G!"I,MW$K1~$8$F(B SGML
|
165 |
|
|
quote $BK!$r;H$C$F!";XDj$9$k$Y$-$G$9!#(B
|
166 |
|
|
</p>
|
167 |
|
|
</div>
|
168 |
|
|
</dd>
|
169 |
|
|
<dt>NONCE</dt>
|
170 |
|
|
<dd>
|
171 |
|
|
<div class="t-pair">
|
172 |
|
|
<p xml:lang="en" class="t-l-en">
|
173 |
|
|
A free-format string (appropriately SGML quoted) which
|
174 |
|
|
is to be included in a SHTTP-Nonce: header (after SGML quoting
|
175 |
|
|
is removed) when the anchor is dereferenced.
|
176 |
|
|
</p>
|
177 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
178 |
|
|
($BE,@Z$K(B SGML quote $B$7$?(B)
|
179 |
|
|
$B<+M37A<0J8;zNs$G!"IE$,2r;2>H(B (dereference) $B$5$l$k;~$K(B
|
180 |
|
|
(SGML $B0zMQId$r>C$7$?8e$G(B) SHTTP-Nonce: $BF,$K4^$a$i$l$k$b$N!#(B
|
181 |
|
|
</p>
|
182 |
|
|
</div>
|
183 |
|
|
</dd>
|
184 |
|
|
<dt>CRYPTOPTS</dt>
|
185 |
|
|
<dd>
|
186 |
|
|
<div class="t-pair">
|
187 |
|
|
<p xml:lang="en" class="t-l-en">
|
188 |
|
|
Cryptographic option information as described in
|
189 |
|
|
<span class="rfc-xref">
|
190 |
|
|
<a href="#SHTTP" title="The Secure HyperText Transfer Protocol">[SHTTP]</a>
|
191 |
|
|
</span>. Specifically, the
|
192 |
|
|
<cryptopt-list> production.
|
193 |
|
|
</p>
|
194 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
195 |
|
|
<a href="#SHTTP" title="$B0BA4D6J8E>Aw%W%m%H%3%k(B">[SHTTP]</a> $B$G@bL@$5$l$?0E9f2=A*Br;h>pJs!#6qBNE*$K$O(B
|
196 |
|
|
<cryptopt-list>$B!#(B
|
197 |
|
|
</p>
|
198 |
|
|
</div>
|
199 |
|
|
</dd>
|
200 |
|
|
</dl>
|
201 |
|
|
</div>
|
202 |
|
|
|
203 |
|
|
<div class="rfc-section" id="rfc.section.2.1">
|
204 |
|
|
<div class="t-pair t-heading" id="html-certs">
|
205 |
|
|
<h2 xml:lang="en" class="t-l-en">2.1. CERTS Element</h2>
|
206 |
|
|
<h2 xml:lang="ja" class="t-l-ja">2.1.
|
207 |
|
|
CERTS $BMWAG(B</h2>
|
208 |
|
|
</div>
|
209 |
|
|
<div class="rfc-t" id="rfc.section.2.1.p.1">
|
210 |
|
|
<div class="t-pair">
|
211 |
|
|
<p xml:lang="en" class="t-l-en">
|
212 |
|
|
A new CERTS HTML element is defined, which carries a
|
213 |
|
|
(not necessarily related) group of certificates provided
|
214 |
|
|
as advisory data. The element contents are not intended to be
|
215 |
|
|
displayed to the user. Certificate groups may be provided
|
216 |
|
|
appropriate for either PEM or PKCS-7 implementations. Such
|
217 |
|
|
certificates are supplied in the HTML document for the
|
218 |
|
|
convenience of the recipient, who might otherwise be unable
|
219 |
|
|
to retrieve the certificate (chain) corresponding to a DN
|
220 |
|
|
specified in an anchor.
|
221 |
|
|
</p>
|
222 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
223 |
|
|
$B?7$7$$(B CERTS $B$H$$$&(B HTML
|
224 |
|
|
$BMWAG$rDj5A$7$^$9!#$3$l$O8\Ld%G!<%?$H$7$FDs6!$5$l$k>ZL@=q$N(B
|
225 |
|
|
($B4XO"$7$F$$$kI,MW$OL5$$(B)
|
226 |
|
|
$B72$r1?HB$7$^$9!#MWAG$NFbMF$OMxMQ<T$KDs<($9$k$3$H$rL\E*$H$7$F$O$$$^$;$s!#>ZL@=q72$O(B
|
227 |
|
|
PEM $B$+(B PKCS-7
|
228 |
|
|
$B$N<BAu$N$I$A$i$+E,@Z$JJ}$rDs6!$7$F9=$$$^$;$s!#$3$N>ZL@=q$O<u?.<T$NJX59$N$?$a$K(B
|
229 |
|
|
HTML
|
230 |
|
|
$BJ8=qCf$KF~$l$k$b$N$G$9$,!"F~$l$F$J$1$l$P(B<a href="#html-a-dn" title="">$BIECf$N(B
|
231 |
|
|
DN</a>
|
232 |
|
|
$B$KBP1~$9$k>ZL@=q(B($B:?(B)$B$r<h$j=P$9$3$H$,=PMh$J$$$+$b$7$l$^$;$s!#(B
|
233 |
|
|
</p>
|
234 |
|
|
</div>
|
235 |
|
|
</div>
|
236 |
|
|
|
237 |
|
|
<div class="rfc-t" id="rfc.section.2.1.p.2">
|
238 |
|
|
<div class="t-pair">
|
239 |
|
|
<p xml:lang="en" class="t-l-en">
|
240 |
|
|
The format should be the same as that of the 'Certificate-Info'
|
241 |
|
|
header line, of <span class="rfc-xref">
|
242 |
|
|
<a href="#SHTTP" title="The Secure HyperText Transfer Protocol">[SHTTP]</a>
|
243 |
|
|
</span> except that the
|
244 |
|
|
<Cert-Fmt> specifier should be provided as the FMT attribute
|
245 |
|
|
in the tag.
|
246 |
|
|
</p>
|
247 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
248 |
|
|
$B=q<0$O(B <a href="#SHTTP" title="$B0BA4D6J8E>Aw%W%m%H%3%k(B">[SHTTP]</a> $B$N(B 'Certificate-Info' $BF,$N$b$N$H!"(B
|
249 |
|
|
<Cert-Fmt> $B;XDj;R$r%?%0$N(B FMT $BB0@-$H$9$k$3$H$r=|$$$FF10l$G$9!#(B
|
250 |
|
|
</p>
|
251 |
|
|
</div>
|
252 |
|
|
</div>
|
253 |
|
|
|
254 |
|
|
<div class="rfc-t" id="rfc.section.2.1.p.3">
|
255 |
|
|
<div class="t-pair">
|
256 |
|
|
<p xml:lang="en" class="t-l-en">
|
257 |
|
|
Multiple CERTS elements are permitted; it is suggested that CERTS
|
258 |
|
|
elements themselves be included in the HTML document's HEAD
|
259 |
|
|
element (in the hope that the data will not be displayed by
|
260 |
|
|
S-HTTP oblivious but HTML compliant browsers.)
|
261 |
|
|
</p>
|
262 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
263 |
|
|
$BJ#?t$N(B CERTS $BMWAG$r;H$C$F$b9=$$$^$;$s!#(B CERTS $BMWAG<+BN$O(B HTML
|
264 |
|
|
$BJ8=q$N(B HEAD $BMWAGCf$K4^$a$k$3$H$r(B (S-HTTP $B$rCN$i$J$$$1$I(B HTML
|
265 |
|
|
$B$K$OE,9g$7$F$$$k%V%i%&%6!<$,%G!<%?$rI=<($7$J$$$3$H$r4j$C$F(B)
|
266 |
|
|
$BDs0F$7$^$9!#(B
|
267 |
|
|
</p>
|
268 |
|
|
</div>
|
269 |
|
|
</div>
|
270 |
|
|
</div>
|
271 |
|
|
|
272 |
|
|
<div class="rfc-section" id="rfc.section.2.2">
|
273 |
|
|
<div class="t-pair t-heading" id="html-cryptopts">
|
274 |
|
|
<h2 xml:lang="en" class="t-l-en">2.2. CRYPTOPTS Element</h2>
|
275 |
|
|
<h2 xml:lang="ja" class="t-l-ja">2.2.
|
276 |
|
|
CRYPTOPTS $BMWAG(B</h2>
|
277 |
|
|
</div>
|
278 |
|
|
<div class="rfc-t" id="rfc.section.2.2.p.1">
|
279 |
|
|
<div class="t-pair">
|
280 |
|
|
<p xml:lang="en" class="t-l-en">
|
281 |
|
|
Cryptopts may also be broken out into an element and referred
|
282 |
|
|
to in anchors by name. The NAME attribute specifies the name
|
283 |
|
|
by which this element may be referred to in a CRYPTOPTS
|
284 |
|
|
attribute in an anchor. Names must have a # as the leading
|
285 |
|
|
character.
|
286 |
|
|
</p>
|
287 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
288 |
|
|
cryptopts $B$bMWAGCf$K8=$l$F(B,
|
289 |
|
|
$BIECf$GL>A0$r;H$C$F;2>H$5$l$k$3$H$,=PMh$^$9!#(B NAME
|
290 |
|
|
$BB0@-$O$3$NMWAG$,(B<a href="#html-a-cryptopts" title="">$BIECf$N(B
|
291 |
|
|
CRYPTOPTS
|
292 |
|
|
$BB0@-(B</a>$BCf$G;2>H$9$k$?$a$NL>A0$r;XDj$7$^$9!#L>A0$O@hF3J8;z$H$7$F(B
|
293 |
|
|
# $B$r;}$?$J$1$l$P$J$j$^$;$s!#(B
|
294 |
|
|
</p>
|
295 |
|
|
</div>
|
296 |
|
|
</div>
|
297 |
|
|
</div>
|
298 |
|
|
|
299 |
|
|
<div class="rfc-section" id="rfc.section.2.3">
|
300 |
|
|
<div class="t-pair t-heading">
|
301 |
|
|
<h2 xml:lang="en" class="t-l-en">2.3. HTML Example</h2>
|
302 |
|
|
<h2 xml:lang="ja" class="t-l-ja">2.3.
|
303 |
|
|
HTML $B$NNc(B</h2>
|
304 |
|
|
</div>
|
305 |
|
|
<div class="rfc-figure">
|
306 |
|
|
<span class="rfc-figure-id" id="rfc.figure.u.1"> </span>
|
307 |
|
|
<div class="rfc-preamble">
|
308 |
|
|
<div class="t-pair">
|
309 |
|
|
<p xml:lang="en" class="t-l-en">
|
310 |
|
|
An example of cryptographic data embedded in an anchor,
|
311 |
|
|
proceeded by a certificate group is provided below. Note the
|
312 |
|
|
SGML quoting syntax used to supply embedded quotation marks.
|
313 |
|
|
</p>
|
314 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
315 |
|
|
$BIE$KKd$a9~$^$l$?0E9f2=%G!<%?$K>ZL@=q72$,B3$/Nc$r<!$K5s$2$^$9!#$J$*!"(B
|
316 |
|
|
SGML quote $B9=J8$rKd$a9~$_0zMQId$K;H$C$F$$$^$9!#(B
|
317 |
|
|
</p>
|
318 |
|
|
</div>
|
319 |
|
|
</div>
|
320 |
|
|
|
321 |
|
|
|
322 |
|
|
<pre class="rfc-artwork" xml:space="preserve"><CERTS FMT=PKCS-7>
|
323 |
|
|
MIAGCSqGSIb3DQEHAqCAMIACAQExADCABgkqhkiG9w0BBwEAAKCAM
|
324 |
|
|
IIBrTCCAUkCAgC2MA0GCSqGSIb3DQEBAgUAME0xCzAJBgNVBAYTAlVTMSAwH
|
325 |
|
|
gYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjEcMBoGA1UECxMTUGVyc
|
326 |
|
|
29uYSBDZXJ0aWZpY2F0ZTAeFw05NDA0MDkwMDUwMzdaFw05NDA4MDIxODM4N
|
327 |
|
|
TdaMGcxCzAJBgNVBAYTAlVTMSAwHgYDVQQKExdSU0EgRGF0YSBTZWN1cml0e
|
328 |
|
|
SwgSW5jLjEcMBoGA1UECxMTUGVyc29uYSBDZXJ0aWZpY2F0ZTEYMBYGA1UEA
|
329 |
|
|
xMPU2V0ZWMgQXN0cm9ub215MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAMy8Q
|
330 |
|
|
cW7RMrB4sTdQ8Nmb2DFmJmkWn+el+NdeamIDElX/qw9mIQu4xNj1FfepfJNx
|
331 |
|
|
zPvA0OtMKhy6+bkrlyMEU8CAwEAATANBgkqhkiG9w0BAQIFAANPAAYn7jDgi
|
332 |
|
|
rhiIL4wnP8nGzUisGSpsFsF4/7z2P2wqne6Qk8Cg/Dstu3RyaN78vAMGP8d8
|
333 |
|
|
2H5+Ndfhi2mRp4YHiGHz0HlK6VbPfnyvS2wdjCCAccwggFRAgUCQAAAFDANB
|
334 |
|
|
gkqhkiG9w0BAQIFADBfMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXUlNBIERhd
|
335 |
|
|
GEgU2VjdXJpdHksIEluYy4xLjAsBgNVBAsTJUxvdyBBc3N1cmFuY2UgQ2Vyd
|
336 |
|
|
GlmaWNhdGlvbiBBdXRob3JpdHkwHhcNOTQwMTA3MDAwMDAwWhcNOTYwMTA3M
|
337 |
|
|
jM1OTU5WjBNMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXUlNBIERhdGEgU2Vjd
|
338 |
|
|
XJpdHksIEluYy4xHDAaBgNVBAsTE1BlcnNvbmEgQ2VydGlmaWNhdGUwaTANB
|
339 |
|
|
gkqhkiG9w0BAQEFAANYADBVAk4GqghQDa9Xi/2zAdYEqJVIcYhlLN1FpI9tX
|
340 |
|
|
Q1m6zZ39PYXK8Uhoj0Es7kWRv8hC04vqkOKwndWbzVtvoHQOmP8nOkkuBi+A
|
341 |
|
|
QvgFoRcgOUCAwEAATANBgkqhkiG9w0BAQIFAANhAD/5Uo7xDdp49oZm9GoNc
|
342 |
|
|
PhZcW1e+nojLvHXWAU/CBkwfcR+FSf4hQ5eFu1AjYv6Wqf430Xe9Et5+jgnM
|
343 |
|
|
Tiq4LnwgTdA8xQX4elJz9QzQobkE3XVOjVAtCFcmiin80RB8AAAMYAAAAAAA
|
344 |
|
|
AAAAA==
|
345 |
|
|
</CERTS>
|
346 |
|
|
<A name=foobar
|
347 |
|
|
DN="CN=Setec Astronomy, OU=Persona Certificate,
|
348 |
|
|
O=&quot;RSA Data Security, Inc.&quot;, C=US"
|
349 |
|
|
CRYPTOPTS="SHTTP-Privacy-Enhancements: recv-refused=encrypt;
|
350 |
|
|
SHTTP-Signature-Algorithms: recv-required=NIST-DSS"
|
351 |
|
|
HREF="shttp://research.nsa.gov/skipjack-holes.html">
|
352 |
|
|
Don't read this. </A>
|
353 |
|
|
</pre>
|
354 |
|
|
|
355 |
|
|
</div>
|
356 |
|
|
</div>
|
357 |
|
|
</div>
|
358 |
|
|
|
359 |
|
|
<div class="rfc-section" id="rfc.section.3">
|
360 |
|
|
<div class="t-pair t-heading">
|
361 |
|
|
<h1 xml:lang="en" class="t-l-en">3. Security Considerations</h1>
|
362 |
|
|
<h1 xml:lang="ja" class="t-l-ja">3.
|
363 |
|
|
$B0BA4@-$K4X$7$F(B</h1>
|
364 |
|
|
</div>
|
365 |
|
|
<div class="rfc-t" id="rfc.section.3.p.1">
|
366 |
|
|
<div class="t-pair">
|
367 |
|
|
<p xml:lang="en" class="t-l-en">
|
368 |
|
|
This entire document is about security.
|
369 |
|
|
</p>
|
370 |
|
|
<p xml:lang="ja" class="t-l-ja">
|
371 |
|
|
$B$3$NJ8=qA4BN$,0BA4@-$K4X$7$F$NOC$G$9!#(B
|
372 |
|
|
</p>
|
373 |
|
|
</div>
|
374 |
|
|
</div>
|
375 |
|
|
</div>
|
376 |
|
|
|
377 |
|
|
<div id="rfc-authors" class="rfc-section">
|
378 |
|
|
<div id="rfc.authors" class="t-pair t-heading">
|
379 |
|
|
<h1 xml:lang="en" class="t-l-en">4. Author's Addresses</h1>
|
380 |
|
|
<h1 xml:lang="ja" class="t-l-ja">4. $BCx<T$NO"Mm@h(B</h1>
|
381 |
|
|
</div>
|
382 |
|
|
<ul class="rfc-author">
|
383 |
|
|
<li class="rfc-author-fullname">Eric Rescorla</li>
|
384 |
|
|
<li class="rfc-organization">RTFM, Inc.</li>
|
385 |
|
|
<li class="rfc-street">30 Newell Road, #16</li>
|
386 |
|
|
<li class="rfc-city">East Palo Alto</li>
|
387 |
|
|
<li class="rfc-region">CA</li>
|
388 |
|
|
<li class="rfc-code">94303</li>
|
389 |
|
|
<li class="rfc-phone">$BEEOC(B: (650) 328-8631</li>
|
390 |
|
|
<li class="rfc-email">$BEE;R%a%$%k(B: <<a href="mailto:ekr@rtfm.com">ekr@rtfm.com</a>></li>
|
391 |
|
|
</ul>
|
392 |
|
|
<ul class="rfc-author">
|
393 |
|
|
<li class="rfc-author-fullname">Allan M. Schiffman</li>
|
394 |
|
|
<li class="rfc-organization">SPYRUS/Terisa</li>
|
395 |
|
|
<li class="rfc-street">5303 Betsy Ross Drive</li>
|
396 |
|
|
<li class="rfc-city">Santa Clara</li>
|
397 |
|
|
<li class="rfc-region">CA</li>
|
398 |
|
|
<li class="rfc-code">95054</li>
|
399 |
|
|
<li class="rfc-phone">$BEEOC(B: (408) 327-1901</li>
|
400 |
|
|
<li class="rfc-email">$BEE;R%a%$%k(B: <<a href="mailto:ams@terisa.com">ams@terisa.com</a>></li>
|
401 |
|
|
</ul>
|
402 |
|
|
</div>
|
403 |
|
|
<div class="rfc-section" id="rfc.references">
|
404 |
|
|
<div class="t-pair t-heading">
|
405 |
|
|
<h1 xml:lang="en" class="t-l-en">5. References</h1>
|
406 |
|
|
<h1 xml:lang="ja" class="t-l-ja">5. $B;29MJ88%(B</h1>
|
407 |
|
|
</div>
|
408 |
|
|
<dl>
|
409 |
|
|
<dt id="SHTTP">[SHTTP]</dt>
|
410 |
|
|
<dd>$B!X(B<cite>The Secure HyperText Transfer Protocol</cite>$B!Y(B<span class="t-pair">
|
411 |
|
|
<span xml:lang="ja" class="t-l-ja">, $B!X(B<cite>$B0BA4D6J8E>Aw%W%m%H%3%k(B</cite>$B!Y(B</span>
|
412 |
|
|
</span>, Rescorla, E., Schiffman, A., <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="URI: <http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660>">RFC 2660</a>$B!#(B</dd>
|
413 |
|
|
</dl>
|
414 |
|
|
</div>
|
415 |
|
|
<div id="rfc-copyright" class="rfc-section">
|
416 |
|
|
<div class="t-pair" id="rfc.copyright">
|
417 |
|
|
<h1 xml:lang="en" class="t-l-en">6. Full Copyright Statement</h1>
|
418 |
|
|
<h1 xml:lang="ja" class="t-l-ja">6. $B40A4$JCx:n8"@<L@(B</h1>
|
419 |
|
|
</div>
|
420 |
|
|
<div class="t-pair t-hide-no">
|
421 |
|
|
<p class="t-l-en" xml:lang="en">
|
422 |
|
|
Copyright ©
|
423 |
|
|
<a href="http://www.isoc.org/">The Internet Society</a>
|
424 |
|
|
(1999).
|
425 |
|
|
All Rights Reserved.
|
426 |
|
|
</p>
|
427 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
428 |
|
|
$BCx:n8"(B ©
|
429 |
|
|
<a href="http://www.isoc.org/">The Internet Society</a>
|
430 |
|
|
(1999)$B!#A48"N1J]!#(B
|
431 |
|
|
</p>
|
432 |
|
|
</div>
|
433 |
|
|
<div class="rfc-t">
|
434 |
|
|
<div class="t-pair t-hide-no">
|
435 |
|
|
<p class="t-l-en" xml:lang="en">
|
436 |
|
|
This document and translations of it may be copied
|
437 |
|
|
and furnished
|
438 |
|
|
to others, and derivative works that comment on or otherwise
|
439 |
|
|
explain it or assist in its implementation may be prepared,
|
440 |
|
|
copied, published and distributed, in whole or in part,
|
441 |
|
|
without restriction of any kind, provided that the
|
442 |
|
|
above copyright notice
|
443 |
|
|
and this paragraph are included on all such copies and
|
444 |
|
|
derivative works. However, this document itself may
|
445 |
|
|
not be modified in any way, such as by removing the
|
446 |
|
|
copyright notice or references to the Internet Society
|
447 |
|
|
or other Internet organizations, except as
|
448 |
|
|
needed for the purpose of developing Internet standards
|
449 |
|
|
in which case the procedures for copyrights defined in
|
450 |
|
|
the Internet Standards process must be followed, or as
|
451 |
|
|
required to translate it into languages other than English.
|
452 |
|
|
</p>
|
453 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
454 |
|
|
$B$3$NJ8=q$H$=$NK]Lu$OJ#<L$7B><T$KDs6!$7$F$bNI$/!"$^$?$3$l$K$D$$$FCm<a$r2C$($k$+$b$7$/$O@bL@$9$k!"$"$k$$$O$=$N<BAu$r=u$1$kGI@8E*:n6H$O!"$=$NA4It$^$?$O0lIt$r!">e5-$NCx:n8"I=<(5Z$S$3$N@a$rA4$F$NJ#<LJ*5Z$SGI@8E*:n6H$K4^$`8B$j$K$*$$$F!"0l@Z$N@)8BL5$7$K!"MQ0U!&J#<L!&=PHG!&G[I[$7$FNI$$!#$7$+$7!"$3$NJ8=q<+BN$O!"Cx:n8"I=<($"$k$$$O(B
|
455 |
|
|
Internet Society $BKt$OB>$N(B Internet
|
456 |
|
|
$BAH?%$X$N8@5Z$r<h$j=|$/$J$I!"$$$+$J$kJ}K!$K$;$hJQ99$7$F$O$J$i$J$$!#C"$7!"(B
|
457 |
|
|
Internet $BI8=`2=2aDx$GDj5A$5$l$?Cx:n8"$N$?$a$N<jB3$-$K=>$$(B
|
458 |
|
|
Internet $BI8=`$r3+H/$9$kL\E*$KI,MW$J>l9g!"$"$k$$$O1Q8l0J30$N8@8l$KK]Lu$9$k$N$KI,MW$J>l9g$r=|$/!#(B
|
459 |
|
|
</p>
|
460 |
|
|
</div>
|
461 |
|
|
</div>
|
462 |
|
|
<div class="rfc-t">
|
463 |
|
|
<div class="t-pair t-hide-no">
|
464 |
|
|
<p class="t-l-en" xml:lang="en">
|
465 |
|
|
The limited permissions granted above are perpetual and will
|
466 |
|
|
not be revoked by the Internet Society or its successors or
|
467 |
|
|
assigns.
|
468 |
|
|
</p>
|
469 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
470 |
|
|
$B>e5-$GG'$a$?$3$N@)8BIU$-5vBz$O915WE*$J$b$N$G$"$j!"(B
|
471 |
|
|
Internet Society $B$b$7$/$O$=$N8e7Q<T$b$7$/$O$=$N>yEO<T$K$h$jGK4~$5$l$k$3$H$O$J$$!#(B
|
472 |
|
|
</p>
|
473 |
|
|
</div>
|
474 |
|
|
</div>
|
475 |
|
|
<div class="rfc-t">
|
476 |
|
|
<div class="t-pair t-hide-no">
|
477 |
|
|
<p class="t-l-en" xml:lang="en">
|
478 |
|
|
This document and the information contained herein is provided
|
479 |
|
|
on an $B!H(B<strong>AS IS</strong>$B!I(B basis and
|
480 |
|
|
<strong>THE INTERNET SOCIETY AND THE INTERNET ENGINEERING
|
481 |
|
|
TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED,
|
482 |
|
|
INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF
|
483 |
|
|
THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY
|
484 |
|
|
IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR
|
485 |
|
|
A PARTICULAR PURPOSE</strong>.
|
486 |
|
|
</p>
|
487 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
488 |
|
|
$B$3$NJ8=q5Z$S$3$3$K4^$^$l$k>pJs$O!V(B<strong>$B8=>uM-;Q(B</strong>$B!W$GDs6!$5$l!"(B
|
489 |
|
|
<strong>Internet Society $B$*$h$S(B
|
490 |
|
|
<a href="http://www.ietf.org/">Internet Engineering Task Force
|
491 |
|
|
(Internet $B5;=QFCJLD4::0Q0w2q(B)</a>
|
492 |
|
|
$B$O$3$3$K4^$^$l$k>pJs$N;HMQ$,$$$+$J$k8"Mx$r$b?/32$7$J$$$H$$$&J]>Z$^$?$O;T>l@-$"$k$$$OFCDjL\E*$X$NE,Ev@-$K$D$$$F$N0EL[E*J]>Z$r4^$a$F$3$l$K8BDj$5$l$J$$!"L@<($"$k$$$O0E<($K$h$k!"0l@Z$NJ]>Z$rH]G'$9$k(B</strong>$B!#(B
|
493 |
|
|
</p>
|
494 |
|
|
</div>
|
495 |
|
|
</div>
|
496 |
|
|
<ins class="t-note t-l-ja" xml:lang="ja">
|
497 |
|
|
<p class="rfc-t">
|
498 |
|
|
(<span class="t-note-title">$BLuCm(B:</span>
|
499 |
|
|
$B@5<0$JCx:n8"@<L@$O1Q8l$N86J8$N$_$G$"$j!"Lu<T$O0l@Z$NJ]>Z(B
|
500 |
|
|
($BK]LuJ8$,86J8$H87L)$K0lCW$7$F$$$k$+$r4^$`$,!"$3$l$K8BDj$5$l$J$$!#(B)
|
501 |
|
|
$B$r(B<strong title="NOT">$B$7$J$$(B</strong>$B!#(B<a href="#rfc-t-copyright">$BLuJ8$K$D$$$F$NCx:n8"@<L@(B</a>$B$b;2>H$;$h!#(B)
|
502 |
|
|
</p>
|
503 |
|
|
</ins>
|
504 |
|
|
</div>
|
505 |
|
|
|
506 |
|
|
<div id="rfc-acknowledgement-editor" class="rfc-section">
|
507 |
|
|
<div class="t-heading t-pair">
|
508 |
|
|
<h1 xml:lang="en" class="t-l-en">Acknowledgement</h1>
|
509 |
|
|
<h1 xml:lang="ja" class="t-l-ja">$B<U<-(B</h1>
|
510 |
|
|
</div>
|
511 |
|
|
<div class="rfc-t">
|
512 |
|
|
<div class="t-pair">
|
513 |
|
|
<p class="t-l-en" xml:lang="en">
|
514 |
|
|
Funding for the
|
515 |
|
|
<a href="http://www.rfceditor.org/">RFC editor</a>
|
516 |
|
|
function is currently provided by the
|
517 |
|
|
<a href="http://www.isoc.org/">Internet Society</a>.
|
518 |
|
|
</p>
|
519 |
|
|
<p class="t-l-ja" xml:lang="ja">
|
520 |
|
|
<a href="http://www.rfceditor.org/" xml:lang="en">RFC
|
521 |
|
|
$BJT=8<T(B</a>$B6HL3$N;q6b1g=u$O8=:_(B
|
522 |
|
|
<a href="http://www.isoc.org/">Internet Society</a>
|
523 |
|
|
$B$K$h$j9T$o$l$F$$$^$9!#(B
|
524 |
|
|
</p>
|
525 |
|
|
</div>
|
526 |
|
|
</div>
|
527 |
|
|
</div>
|
528 |
|
|
<ins id="rfc-translators-note" class="t-note t-l-ja" xml:lang="ja">
|
529 |
|
|
<div class="rfc-section" id="t-change">
|
530 |
|
|
<h1>$BK]Lu$NJQ99MzNr(B</h1>
|
531 |
|
|
<dl>
|
532 |
|
|
<dt>2002-05-12 <a href="mailto:w@suika.fam.cx" title="$BEE;R%a%$%k(B: <w@suika.fam.cx>">$B$o$+$P(B</a>
|
533 |
|
|
</dt>
|
534 |
|
|
<dd>
|
535 |
|
|
<ul>
|
536 |
|
|
<li>$BF|K\8l$KK]Lu!#(B</li>
|
537 |
|
|
</ul>
|
538 |
|
|
</dd>
|
539 |
|
|
<dt>2002-05-26 <a href="mailto:w@suika.fam.cx" title="$BEE;R%a%$%k(B: <w@suika.fam.cx>">$B$o$+$P(B</a>
|
540 |
|
|
</dt>
|
541 |
|
|
<dd>
|
542 |
|
|
<ul>
|
543 |
|
|
<li>
|
544 |
|
|
<a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2629" title="RFC 2629">RFC 2629</a> $B$G%^!<%/IU$1!#(B</li>
|
545 |
|
|
</ul>
|
546 |
|
|
</dd>
|
547 |
|
|
</dl>
|
548 |
|
|
</div>
|
549 |
|
|
<div class="rfc-section" id="rfc-t-copyright">
|
550 |
|
|
<h1>$BLuJ8$K$D$$$F$NCx:n8"@<L@(B</h1>
|
551 |
|
|
<p>
|
552 |
|
|
<a href="#rfc-copyright">$B86J8$NCx:n8"@<L@(B</a>$B$,!"LuJ8$K$D$$$F$bF1MM$KE,MQ$5$l$^$9!#(B</p>
|
553 |
|
|
<p>$B$^$?!"2~Lu$=$NB>$N86J8$NCx:n8"@<L@$KH?$7$J$$HO0O$K$*$1$k2~JQ$O!"0l@Z$N5v2DL5$/9T$C$F9=$$$^$;$s!#(B</p>
|
554 |
|
|
</div>
|
555 |
|
|
</ins>
|
556 |
|
|
</body>
|
557 |
|
|
</html>
|