| 1 | <?xml version="1.0" encoding="iso-2022-jp"?> | 
| 2 | <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd"> | 
| 3 | <html xmlns:h="http://www.w3.org/1999/xhtml" xmlns="http://www.w3.org/1999/xhtml"> | 
| 4 | <head profile="http://suika.fam.cx/~wakaba/lang/rfc/translation/html-profile"> | 
| 5 | <meta http-equiv="Content-Style-Type" content="text/css"/> | 
| 6 | <title> | 
| 7 | RFC 2659: | 
| 8 | HTML$B$N0BA4@-3HD%(B (Security Extensions For HTML) | 
| 9 | </title> | 
| 10 | <link rel="stylesheet" href="http://suika.fam.cx/~wakaba/lang/rfc/translation/rfc-ja-style.css" type="text/css"/> | 
| 11 | <link rel="alternate" href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2659" hreflang="en" title="RFC 2659"/> | 
| 12 | <link rev="made" href="http://www.rfceditor.org/" title="RFC Editor"/> | 
| 13 | <link rev="translate" href="#rfc-translators-note"/> | 
| 14 | <meta name="author" content="Eric Rescorla, Allan M. Schiffman, "/> | 
| 15 | </head> | 
| 16 | <body> | 
| 17 | <div id="rfc--table"> | 
| 18 | <ul id="rfc--table-left"> | 
| 19 | <li>Network Working Group</li> | 
| 20 | <li>Request for Comments: 2659</li> | 
| 21 | <li> | 
| 22 | <span class="t-pair"> | 
| 23 | <span xml:lang="en" class="t-l-en">Category: Experimental</span> | 
| 24 | </span> | 
| 25 | </li> | 
| 26 | <li> | 
| 27 | <span class="t-pair"> | 
| 28 | <span xml:lang="ja" class="t-l-ja">$BJ,N`(B: $B<B83E*(B</span> | 
| 29 | </span> | 
| 30 | </li> | 
| 31 | </ul> | 
| 32 | <ul id="rfc--table-right"> | 
| 33 | <li title="Eric Rescorla">E. Rescorla</li> | 
| 34 | <li>RTFM, Inc.</li> | 
| 35 | <li title="Allan M. Schiffman">A. Schiffman</li> | 
| 36 | <li title="SPYRUS/Terisa">Terisa Systems, Inc.</li> | 
| 37 | <li> | 
| 38 | <span class="t-pair"> | 
| 39 | <span xml:lang="en" class="t-l-en"> August 1999</span> | 
| 40 | </span> | 
| 41 | </li> | 
| 42 | <li> | 
| 43 | <span class="t-pair"> | 
| 44 | <span xml:lang="ja" class="t-l-ja">1999$BG/(B8$B7n(B</span> | 
| 45 | </span> | 
| 46 | </li> | 
| 47 | </ul> | 
| 48 | </div> | 
| 49 | <div class="t-pair t-heading" id="rfc-title"> | 
| 50 | <h1 class="rfc-title t-l-en" xml:lang="en">Security Extensions For HTML</h1> | 
| 51 | <h1 class="rfc-title t-l-ja" xml:lang="ja">HTML$B$N0BA4@-3HD%(B</h1> | 
| 52 | </div> | 
| 53 | <div id="rfc-status" class="rfc-section"> | 
| 54 | <div class="t-pair"> | 
| 55 | <h1 xml:lang="en" class="t-l-en">Status of this Memo</h1> | 
| 56 | <h1 xml:lang="ja" class="t-l-ja">$B$3$N%a%b$N0LCVIU$1(B</h1> | 
| 57 | </div> | 
| 58 | <div class="rfc-t"> | 
| 59 | <div class="t-pair"> | 
| 60 | <p class="t-l-en" xml:lang="en"> | 
| 61 | This memo defines an Experimental Protocol for the Internet community. | 
| 62 | It does not specify an Internet standard of any kind. | 
| 63 | Discussion and suggestions for improvement are requested. | 
| 64 | Distribution of this memo is unlimited. | 
| 65 | </p> | 
| 66 | <p class="t-l-ja" xml:lang="ja"> | 
| 67 | $B$3$N%a%b$O!"(B Internet $B<R2q8~$1$N<B83E*%W%m%H%3%k$rDj5A$9$k$b$N$G$9!#$$$+$J$k<oN`$N(B | 
| 68 | Internet $BI8=`$r5,Dj$9$k$b$N$G$b$"$j$^$;$s!#2~NI$N0Y$N5DO@$dDs0F$r5a$a$^$9!#$3$N%a%b$NG[I[$O@)8B$7$^$;$s!#(B | 
| 69 | </p> | 
| 70 | </div> | 
| 71 | </div> | 
| 72 | </div> | 
| 73 | <div id="rfc-copyright-notice" class="rfc-section"> | 
| 74 | <div class="t-pair"> | 
| 75 | <h1 xml:lang="en" class="t-l-en">Copyright Notice</h1> | 
| 76 | <h1 xml:lang="ja" class="t-l-ja">$BCx:n8"I=<((B</h1> | 
| 77 | </div> | 
| 78 | <div class="t-pair t-hide-no"> | 
| 79 | <p class="t-l-en" xml:lang="en">Copyright © | 
| 80 | <a href="http://www.isoc.org/">The Internet Society</a> | 
| 81 | (1999). | 
| 82 | All Rights Reserved.</p> | 
| 83 | <p class="t-l-ja" xml:lang="ja">$BCx:n8"(B © | 
| 84 | <a href="http://www.isoc.org/">The Internet Society</a> | 
| 85 | (1999)$B!#A48"J]N1!#(B</p> | 
| 86 | </div> | 
| 87 | </div> | 
| 88 | <div class="rfc-section" id="rfc.abstract"> | 
| 89 | <div class="t-pair t-heading"> | 
| 90 | <h1 xml:lang="en" class="t-l-en">Abstract</h1> | 
| 91 | <h1 xml:lang="ja" class="t-l-ja">$B35MW(B</h1> | 
| 92 | </div> | 
| 93 | <div class="rfc-t"> | 
| 94 | <div class="t-pair"> | 
| 95 | <p xml:lang="en" class="t-l-en"> | 
| 96 | This memo describes a syntax for embedding S-HTTP negotiation | 
| 97 | parameters in HTML documents.  S-HTTP, as described by | 
| 98 | <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="RFC 2660">RFC 2660</a>, contains the concept of | 
| 99 | negotiation headers which reflect the potential receiver of | 
| 100 | a message's preferences as to which cryptographic enhancements | 
| 101 | should be applied to the message. This document describes a | 
| 102 | syntax for binding these negotiation parameters to HTML anchors. | 
| 103 | </p> | 
| 104 | <p xml:lang="ja" class="t-l-ja"> | 
| 105 | $B$3$N%a%b$O!"(B HTML $BJ8=qCf$K(B S-HTTP | 
| 106 | $B@^>W%Q%i%a!<%?!<$rKd$a9~$`9=J8$r@bL@$7$^$9!#(B | 
| 107 | <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="RFC 2660">RFC 2660</a> $B$G@bL@$5$l$F$$$k(B | 
| 108 | S-HTTP $B$O!"$I$N0E9f3HD%$r%a%C%;!<%8$KE,MQ$9$k$+$N!"%a%C%;!<%8$N@x:_<u?.<T$N9%$_$rH?1G$9$k@^>WF,$N35G0$r4^$s$G$$$^$9!#$3$NJ8=q$O$3$l$i$N@^>W%Q%i%a!<%?!<$r(B | 
| 109 | HTML $BIE$KG{$jIU$1$k9=J8$r@bL@$7$^$9!#(B | 
| 110 | </p> | 
| 111 | </div> | 
| 112 | </div> | 
| 113 | </div> | 
| 114 |  | 
| 115 | <div class="rfc-section" id="rfc.section.1"> | 
| 116 | <div class="t-pair t-heading"> | 
| 117 | <h1 xml:lang="en" class="t-l-en">1. Introduction</h1> | 
| 118 | <h1 xml:lang="ja" class="t-l-ja">1. | 
| 119 | $B$O$8$a$K(B</h1> | 
| 120 | </div> | 
| 121 | <ins class="t-note t-l-ja" xml:lang="ja"> | 
| 122 | <span class="t-note-title">$BLuCm(B: </span> | 
| 123 | <p class="rfc-t" id="rfc.section.1.p.1">$B86J8$G7gMn!#(B</p> | 
| 124 | </ins> | 
| 125 | </div> | 
| 126 |  | 
| 127 | <div class="rfc-section" id="rfc.section.2"> | 
| 128 | <div class="t-pair t-heading"> | 
| 129 | <h1 xml:lang="en" class="t-l-en">2. Anchor Attributes</h1> | 
| 130 | <h1 xml:lang="ja" class="t-l-ja">2. | 
| 131 | $BIEB0@-(B</h1> | 
| 132 | </div> | 
| 133 | <div class="rfc-t" id="rfc.section.2.p.1"> | 
| 134 | <div class="t-pair"> | 
| 135 | <p xml:lang="en" class="t-l-en"> | 
| 136 | We define the following new anchor (and form submission) attributes: | 
| 137 | </p> | 
| 138 | <p xml:lang="ja" class="t-l-ja"> | 
| 139 | $B<!$N?7$7$$IE(B ($B$H(B form $BAw?.(B) $BB0@-$rDj5A$7$^$9!#(B | 
| 140 | </p> | 
| 141 | </div> | 
| 142 |  | 
| 143 | <dl class="rfc-list-hanging"> | 
| 144 | <dt id="html-a-dn"> | 
| 145 | <a href="#html-a-dn" class="self">DN</a> | 
| 146 | </dt> | 
| 147 | <dd> | 
| 148 | <div class="t-pair"> | 
| 149 | <p xml:lang="en" class="t-l-en"> | 
| 150 | The distinguished name of the principal for whom the | 
| 151 | request should be encrypted when dereferencing the anchor's url. | 
| 152 | This need not be specified, but failure to do so runs the risk | 
| 153 | that the client will be unable to determine the DN and therefore | 
| 154 | will be unable to encrypt.  This should be specified in the form | 
| 155 | of <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:1485" title="RFC 1485">RFC1485</a>, | 
| 156 | using SGML quoting conventions as needed. | 
| 157 | </p> | 
| 158 | <p xml:lang="ja" class="t-l-ja"> | 
| 159 | $BIE$N(B url | 
| 160 | $B$r2r;2>H(B (dereference) $B$9$k;~$KMW5a$,0E9f2=$9$k$Y$-BP>]<T$N<1JL$5$l$?L>A0!#(B | 
| 161 | $B$3$l$O;XDj$9$kI,MW$O$"$j$^$;$s$,!"%/%i%$%"%s%H$,(B DN | 
| 162 | $B$r7hDj=PMh$:!"$R$$$F$O0E9f2=$b=PMh$J$/$J$k4m81$rKA$9$3$H$K$J$j$^$9!#(B | 
| 163 | <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:1485" title="RFC 1485">RFC 1485</a> | 
| 164 | $B$N7A<0$G!"I,MW$K1~$8$F(B SGML | 
| 165 | quote $BK!$r;H$C$F!";XDj$9$k$Y$-$G$9!#(B | 
| 166 | </p> | 
| 167 | </div> | 
| 168 | </dd> | 
| 169 | <dt>NONCE</dt> | 
| 170 | <dd> | 
| 171 | <div class="t-pair"> | 
| 172 | <p xml:lang="en" class="t-l-en"> | 
| 173 | A free-format string (appropriately SGML quoted) which | 
| 174 | is to be included in a SHTTP-Nonce: header (after SGML quoting | 
| 175 | is removed) when the anchor is dereferenced. | 
| 176 | </p> | 
| 177 | <p xml:lang="ja" class="t-l-ja"> | 
| 178 | ($BE,@Z$K(B SGML  quote $B$7$?(B) | 
| 179 | $B<+M37A<0J8;zNs$G!"IE$,2r;2>H(B (dereference) $B$5$l$k;~$K(B | 
| 180 | (SGML $B0zMQId$r>C$7$?8e$G(B) SHTTP-Nonce: $BF,$K4^$a$i$l$k$b$N!#(B | 
| 181 | </p> | 
| 182 | </div> | 
| 183 | </dd> | 
| 184 | <dt>CRYPTOPTS</dt> | 
| 185 | <dd> | 
| 186 | <div class="t-pair"> | 
| 187 | <p xml:lang="en" class="t-l-en"> | 
| 188 | Cryptographic option information as described in | 
| 189 | <span class="rfc-xref"> | 
| 190 | <a href="#SHTTP" title="The Secure HyperText Transfer Protocol">[SHTTP]</a> | 
| 191 | </span>. Specifically, the | 
| 192 | <cryptopt-list> production. | 
| 193 | </p> | 
| 194 | <p xml:lang="ja" class="t-l-ja"> | 
| 195 | <a href="#SHTTP" title="$B0BA4D6J8E>Aw%W%m%H%3%k(B">[SHTTP]</a> $B$G@bL@$5$l$?0E9f2=A*Br;h>pJs!#6qBNE*$K$O(B | 
| 196 | <cryptopt-list>$B!#(B | 
| 197 | </p> | 
| 198 | </div> | 
| 199 | </dd> | 
| 200 | </dl> | 
| 201 | </div> | 
| 202 |  | 
| 203 | <div class="rfc-section" id="rfc.section.2.1"> | 
| 204 | <div class="t-pair t-heading" id="html-certs"> | 
| 205 | <h2 xml:lang="en" class="t-l-en">2.1. CERTS Element</h2> | 
| 206 | <h2 xml:lang="ja" class="t-l-ja">2.1. | 
| 207 | CERTS $BMWAG(B</h2> | 
| 208 | </div> | 
| 209 | <div class="rfc-t" id="rfc.section.2.1.p.1"> | 
| 210 | <div class="t-pair"> | 
| 211 | <p xml:lang="en" class="t-l-en"> | 
| 212 | A new CERTS HTML element is defined, which carries a | 
| 213 | (not necessarily related) group of certificates provided | 
| 214 | as advisory data. The element contents are not intended to be | 
| 215 | displayed to the user. Certificate groups may be provided | 
| 216 | appropriate for either PEM or PKCS-7 implementations. Such | 
| 217 | certificates are supplied in the HTML document for the | 
| 218 | convenience of the recipient, who might otherwise be unable | 
| 219 | to retrieve the certificate (chain) corresponding to a DN | 
| 220 | specified in an anchor. | 
| 221 | </p> | 
| 222 | <p xml:lang="ja" class="t-l-ja"> | 
| 223 | $B?7$7$$(B CERTS $B$H$$$&(B HTML | 
| 224 | $BMWAG$rDj5A$7$^$9!#$3$l$O8\Ld%G!<%?$H$7$FDs6!$5$l$k>ZL@=q$N(B | 
| 225 | ($B4XO"$7$F$$$kI,MW$OL5$$(B) | 
| 226 | $B72$r1?HB$7$^$9!#MWAG$NFbMF$OMxMQ<T$KDs<($9$k$3$H$rL\E*$H$7$F$O$$$^$;$s!#>ZL@=q72$O(B | 
| 227 | PEM $B$+(B PKCS-7 | 
| 228 | $B$N<BAu$N$I$A$i$+E,@Z$JJ}$rDs6!$7$F9=$$$^$;$s!#$3$N>ZL@=q$O<u?.<T$NJX59$N$?$a$K(B | 
| 229 | HTML | 
| 230 | $BJ8=qCf$KF~$l$k$b$N$G$9$,!"F~$l$F$J$1$l$P(B<a href="#html-a-dn" title="">$BIECf$N(B | 
| 231 | DN</a> | 
| 232 | $B$KBP1~$9$k>ZL@=q(B($B:?(B)$B$r<h$j=P$9$3$H$,=PMh$J$$$+$b$7$l$^$;$s!#(B | 
| 233 | </p> | 
| 234 | </div> | 
| 235 | </div> | 
| 236 |  | 
| 237 | <div class="rfc-t" id="rfc.section.2.1.p.2"> | 
| 238 | <div class="t-pair"> | 
| 239 | <p xml:lang="en" class="t-l-en"> | 
| 240 | The format should be the same as that of the 'Certificate-Info' | 
| 241 | header line, of <span class="rfc-xref"> | 
| 242 | <a href="#SHTTP" title="The Secure HyperText Transfer Protocol">[SHTTP]</a> | 
| 243 | </span> except that the | 
| 244 | <Cert-Fmt> specifier should be provided as the FMT attribute | 
| 245 | in the tag. | 
| 246 | </p> | 
| 247 | <p xml:lang="ja" class="t-l-ja"> | 
| 248 | $B=q<0$O(B <a href="#SHTTP" title="$B0BA4D6J8E>Aw%W%m%H%3%k(B">[SHTTP]</a> $B$N(B 'Certificate-Info' $BF,$N$b$N$H!"(B | 
| 249 | <Cert-Fmt> $B;XDj;R$r%?%0$N(B FMT $BB0@-$H$9$k$3$H$r=|$$$FF10l$G$9!#(B | 
| 250 | </p> | 
| 251 | </div> | 
| 252 | </div> | 
| 253 |  | 
| 254 | <div class="rfc-t" id="rfc.section.2.1.p.3"> | 
| 255 | <div class="t-pair"> | 
| 256 | <p xml:lang="en" class="t-l-en"> | 
| 257 | Multiple CERTS elements are permitted; it is suggested that CERTS | 
| 258 | elements themselves be included in the HTML document's HEAD | 
| 259 | element (in the hope that the data will not be displayed by | 
| 260 | S-HTTP oblivious but HTML compliant browsers.) | 
| 261 | </p> | 
| 262 | <p xml:lang="ja" class="t-l-ja"> | 
| 263 | $BJ#?t$N(B CERTS $BMWAG$r;H$C$F$b9=$$$^$;$s!#(B CERTS $BMWAG<+BN$O(B HTML | 
| 264 | $BJ8=q$N(B HEAD $BMWAGCf$K4^$a$k$3$H$r(B (S-HTTP $B$rCN$i$J$$$1$I(B HTML | 
| 265 | $B$K$OE,9g$7$F$$$k%V%i%&%6!<$,%G!<%?$rI=<($7$J$$$3$H$r4j$C$F(B) | 
| 266 | $BDs0F$7$^$9!#(B | 
| 267 | </p> | 
| 268 | </div> | 
| 269 | </div> | 
| 270 | </div> | 
| 271 |  | 
| 272 | <div class="rfc-section" id="rfc.section.2.2"> | 
| 273 | <div class="t-pair t-heading" id="html-cryptopts"> | 
| 274 | <h2 xml:lang="en" class="t-l-en">2.2. CRYPTOPTS Element</h2> | 
| 275 | <h2 xml:lang="ja" class="t-l-ja">2.2. | 
| 276 | CRYPTOPTS $BMWAG(B</h2> | 
| 277 | </div> | 
| 278 | <div class="rfc-t" id="rfc.section.2.2.p.1"> | 
| 279 | <div class="t-pair"> | 
| 280 | <p xml:lang="en" class="t-l-en"> | 
| 281 | Cryptopts may also be broken out into an element and referred | 
| 282 | to in anchors by name. The NAME attribute specifies the name | 
| 283 | by which this element may be referred to in a CRYPTOPTS | 
| 284 | attribute in an anchor. Names must have a # as the leading | 
| 285 | character. | 
| 286 | </p> | 
| 287 | <p xml:lang="ja" class="t-l-ja"> | 
| 288 | cryptopts $B$bMWAGCf$K8=$l$F(B, | 
| 289 | $BIECf$GL>A0$r;H$C$F;2>H$5$l$k$3$H$,=PMh$^$9!#(B NAME | 
| 290 | $BB0@-$O$3$NMWAG$,(B<a href="#html-a-cryptopts" title="">$BIECf$N(B | 
| 291 | CRYPTOPTS | 
| 292 | $BB0@-(B</a>$BCf$G;2>H$9$k$?$a$NL>A0$r;XDj$7$^$9!#L>A0$O@hF3J8;z$H$7$F(B | 
| 293 | # $B$r;}$?$J$1$l$P$J$j$^$;$s!#(B | 
| 294 | </p> | 
| 295 | </div> | 
| 296 | </div> | 
| 297 | </div> | 
| 298 |  | 
| 299 | <div class="rfc-section" id="rfc.section.2.3"> | 
| 300 | <div class="t-pair t-heading"> | 
| 301 | <h2 xml:lang="en" class="t-l-en">2.3. HTML Example</h2> | 
| 302 | <h2 xml:lang="ja" class="t-l-ja">2.3. | 
| 303 | HTML $B$NNc(B</h2> | 
| 304 | </div> | 
| 305 | <div class="rfc-figure"> | 
| 306 | <span class="rfc-figure-id" id="rfc.figure.u.1"> </span> | 
| 307 | <div class="rfc-preamble"> | 
| 308 | <div class="t-pair"> | 
| 309 | <p xml:lang="en" class="t-l-en"> | 
| 310 | An example of cryptographic data embedded in an anchor, | 
| 311 | proceeded by a certificate group is provided below. Note the | 
| 312 | SGML quoting syntax used to supply embedded quotation marks. | 
| 313 | </p> | 
| 314 | <p xml:lang="ja" class="t-l-ja"> | 
| 315 | $BIE$KKd$a9~$^$l$?0E9f2=%G!<%?$K>ZL@=q72$,B3$/Nc$r<!$K5s$2$^$9!#$J$*!"(B | 
| 316 | SGML  quote $B9=J8$rKd$a9~$_0zMQId$K;H$C$F$$$^$9!#(B | 
| 317 | </p> | 
| 318 | </div> | 
| 319 | </div> | 
| 320 |  | 
| 321 |  | 
| 322 | <pre class="rfc-artwork" xml:space="preserve"><CERTS FMT=PKCS-7> | 
| 323 | MIAGCSqGSIb3DQEHAqCAMIACAQExADCABgkqhkiG9w0BBwEAAKCAM | 
| 324 | IIBrTCCAUkCAgC2MA0GCSqGSIb3DQEBAgUAME0xCzAJBgNVBAYTAlVTMSAwH | 
| 325 | gYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjEcMBoGA1UECxMTUGVyc | 
| 326 | 29uYSBDZXJ0aWZpY2F0ZTAeFw05NDA0MDkwMDUwMzdaFw05NDA4MDIxODM4N | 
| 327 | TdaMGcxCzAJBgNVBAYTAlVTMSAwHgYDVQQKExdSU0EgRGF0YSBTZWN1cml0e | 
| 328 | SwgSW5jLjEcMBoGA1UECxMTUGVyc29uYSBDZXJ0aWZpY2F0ZTEYMBYGA1UEA | 
| 329 | xMPU2V0ZWMgQXN0cm9ub215MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAMy8Q | 
| 330 | cW7RMrB4sTdQ8Nmb2DFmJmkWn+el+NdeamIDElX/qw9mIQu4xNj1FfepfJNx | 
| 331 | zPvA0OtMKhy6+bkrlyMEU8CAwEAATANBgkqhkiG9w0BAQIFAANPAAYn7jDgi | 
| 332 | rhiIL4wnP8nGzUisGSpsFsF4/7z2P2wqne6Qk8Cg/Dstu3RyaN78vAMGP8d8 | 
| 333 | 2H5+Ndfhi2mRp4YHiGHz0HlK6VbPfnyvS2wdjCCAccwggFRAgUCQAAAFDANB | 
| 334 | gkqhkiG9w0BAQIFADBfMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXUlNBIERhd | 
| 335 | GEgU2VjdXJpdHksIEluYy4xLjAsBgNVBAsTJUxvdyBBc3N1cmFuY2UgQ2Vyd | 
| 336 | GlmaWNhdGlvbiBBdXRob3JpdHkwHhcNOTQwMTA3MDAwMDAwWhcNOTYwMTA3M | 
| 337 | jM1OTU5WjBNMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXUlNBIERhdGEgU2Vjd | 
| 338 | XJpdHksIEluYy4xHDAaBgNVBAsTE1BlcnNvbmEgQ2VydGlmaWNhdGUwaTANB | 
| 339 | gkqhkiG9w0BAQEFAANYADBVAk4GqghQDa9Xi/2zAdYEqJVIcYhlLN1FpI9tX | 
| 340 | Q1m6zZ39PYXK8Uhoj0Es7kWRv8hC04vqkOKwndWbzVtvoHQOmP8nOkkuBi+A | 
| 341 | QvgFoRcgOUCAwEAATANBgkqhkiG9w0BAQIFAANhAD/5Uo7xDdp49oZm9GoNc | 
| 342 | PhZcW1e+nojLvHXWAU/CBkwfcR+FSf4hQ5eFu1AjYv6Wqf430Xe9Et5+jgnM | 
| 343 | Tiq4LnwgTdA8xQX4elJz9QzQobkE3XVOjVAtCFcmiin80RB8AAAMYAAAAAAA | 
| 344 | AAAAA== | 
| 345 | </CERTS> | 
| 346 | <A name=foobar | 
| 347 | DN="CN=Setec Astronomy, OU=Persona Certificate, | 
| 348 | O=&quot;RSA Data Security, Inc.&quot;, C=US" | 
| 349 | CRYPTOPTS="SHTTP-Privacy-Enhancements: recv-refused=encrypt; | 
| 350 | SHTTP-Signature-Algorithms: recv-required=NIST-DSS" | 
| 351 | HREF="shttp://research.nsa.gov/skipjack-holes.html"> | 
| 352 | Don't read this. </A> | 
| 353 | </pre> | 
| 354 |  | 
| 355 | </div> | 
| 356 | </div> | 
| 357 | </div> | 
| 358 |  | 
| 359 | <div class="rfc-section" id="rfc.section.3"> | 
| 360 | <div class="t-pair t-heading"> | 
| 361 | <h1 xml:lang="en" class="t-l-en">3. Security Considerations</h1> | 
| 362 | <h1 xml:lang="ja" class="t-l-ja">3. | 
| 363 | $B0BA4@-$K4X$7$F(B</h1> | 
| 364 | </div> | 
| 365 | <div class="rfc-t" id="rfc.section.3.p.1"> | 
| 366 | <div class="t-pair"> | 
| 367 | <p xml:lang="en" class="t-l-en"> | 
| 368 | This entire document is about security. | 
| 369 | </p> | 
| 370 | <p xml:lang="ja" class="t-l-ja"> | 
| 371 | $B$3$NJ8=qA4BN$,0BA4@-$K4X$7$F$NOC$G$9!#(B | 
| 372 | </p> | 
| 373 | </div> | 
| 374 | </div> | 
| 375 | </div> | 
| 376 |  | 
| 377 | <div id="rfc-authors" class="rfc-section"> | 
| 378 | <div id="rfc.authors" class="t-pair t-heading"> | 
| 379 | <h1 xml:lang="en" class="t-l-en">4. Author's Addresses</h1> | 
| 380 | <h1 xml:lang="ja" class="t-l-ja">4. $BCx<T$NO"Mm@h(B</h1> | 
| 381 | </div> | 
| 382 | <ul class="rfc-author"> | 
| 383 | <li class="rfc-author-fullname">Eric Rescorla</li> | 
| 384 | <li class="rfc-organization">RTFM, Inc.</li> | 
| 385 | <li class="rfc-street">30 Newell Road, #16</li> | 
| 386 | <li class="rfc-city">East Palo Alto</li> | 
| 387 | <li class="rfc-region">CA</li> | 
| 388 | <li class="rfc-code">94303</li> | 
| 389 | <li class="rfc-phone">$BEEOC(B: (650) 328-8631</li> | 
| 390 | <li class="rfc-email">$BEE;R%a%$%k(B: <<a href="mailto:ekr@rtfm.com">ekr@rtfm.com</a>></li> | 
| 391 | </ul> | 
| 392 | <ul class="rfc-author"> | 
| 393 | <li class="rfc-author-fullname">Allan M. Schiffman</li> | 
| 394 | <li class="rfc-organization">SPYRUS/Terisa</li> | 
| 395 | <li class="rfc-street">5303 Betsy Ross Drive</li> | 
| 396 | <li class="rfc-city">Santa Clara</li> | 
| 397 | <li class="rfc-region">CA</li> | 
| 398 | <li class="rfc-code">95054</li> | 
| 399 | <li class="rfc-phone">$BEEOC(B: (408) 327-1901</li> | 
| 400 | <li class="rfc-email">$BEE;R%a%$%k(B: <<a href="mailto:ams@terisa.com">ams@terisa.com</a>></li> | 
| 401 | </ul> | 
| 402 | </div> | 
| 403 | <div class="rfc-section" id="rfc.references"> | 
| 404 | <div class="t-pair t-heading"> | 
| 405 | <h1 xml:lang="en" class="t-l-en">5. References</h1> | 
| 406 | <h1 xml:lang="ja" class="t-l-ja">5. $B;29MJ88%(B</h1> | 
| 407 | </div> | 
| 408 | <dl> | 
| 409 | <dt id="SHTTP">[SHTTP]</dt> | 
| 410 | <dd>$B!X(B<cite>The Secure HyperText Transfer Protocol</cite>$B!Y(B<span class="t-pair"> | 
| 411 | <span xml:lang="ja" class="t-l-ja">, $B!X(B<cite>$B0BA4D6J8E>Aw%W%m%H%3%k(B</cite>$B!Y(B</span> | 
| 412 | </span>, Rescorla, E., Schiffman, A., <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660" title="URI: <http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2660>">RFC 2660</a>$B!#(B</dd> | 
| 413 | </dl> | 
| 414 | </div> | 
| 415 | <div id="rfc-copyright" class="rfc-section"> | 
| 416 | <div class="t-pair" id="rfc.copyright"> | 
| 417 | <h1 xml:lang="en" class="t-l-en">6. Full Copyright Statement</h1> | 
| 418 | <h1 xml:lang="ja" class="t-l-ja">6. $B40A4$JCx:n8"@<L@(B</h1> | 
| 419 | </div> | 
| 420 | <div class="t-pair t-hide-no"> | 
| 421 | <p class="t-l-en" xml:lang="en"> | 
| 422 | Copyright © | 
| 423 | <a href="http://www.isoc.org/">The Internet Society</a> | 
| 424 | (1999). | 
| 425 | All Rights Reserved. | 
| 426 | </p> | 
| 427 | <p class="t-l-ja" xml:lang="ja"> | 
| 428 | $BCx:n8"(B © | 
| 429 | <a href="http://www.isoc.org/">The Internet Society</a> | 
| 430 | (1999)$B!#A48"N1J]!#(B | 
| 431 | </p> | 
| 432 | </div> | 
| 433 | <div class="rfc-t"> | 
| 434 | <div class="t-pair t-hide-no"> | 
| 435 | <p class="t-l-en" xml:lang="en"> | 
| 436 | This document and translations of it may be copied | 
| 437 | and furnished | 
| 438 | to others, and derivative works that comment on or otherwise | 
| 439 | explain it or assist in its implementation may be prepared, | 
| 440 | copied, published and distributed, in whole or in part, | 
| 441 | without restriction of any kind, provided that the | 
| 442 | above copyright notice | 
| 443 | and this paragraph are included on all such copies and | 
| 444 | derivative works. However, this document itself may | 
| 445 | not be modified in any way, such as by removing the | 
| 446 | copyright notice or references to the Internet Society | 
| 447 | or other Internet organizations, except as | 
| 448 | needed for the purpose of developing Internet standards | 
| 449 | in which case the procedures for copyrights defined in | 
| 450 | the Internet Standards process must be followed, or as | 
| 451 | required to translate it into languages other than English. | 
| 452 | </p> | 
| 453 | <p class="t-l-ja" xml:lang="ja"> | 
| 454 | $B$3$NJ8=q$H$=$NK]Lu$OJ#<L$7B><T$KDs6!$7$F$bNI$/!"$^$?$3$l$K$D$$$FCm<a$r2C$($k$+$b$7$/$O@bL@$9$k!"$"$k$$$O$=$N<BAu$r=u$1$kGI@8E*:n6H$O!"$=$NA4It$^$?$O0lIt$r!">e5-$NCx:n8"I=<(5Z$S$3$N@a$rA4$F$NJ#<LJ*5Z$SGI@8E*:n6H$K4^$`8B$j$K$*$$$F!"0l@Z$N@)8BL5$7$K!"MQ0U!&J#<L!&=PHG!&G[I[$7$FNI$$!#$7$+$7!"$3$NJ8=q<+BN$O!"Cx:n8"I=<($"$k$$$O(B | 
| 455 | Internet Society $BKt$OB>$N(B Internet | 
| 456 | $BAH?%$X$N8@5Z$r<h$j=|$/$J$I!"$$$+$J$kJ}K!$K$;$hJQ99$7$F$O$J$i$J$$!#C"$7!"(B | 
| 457 | Internet $BI8=`2=2aDx$GDj5A$5$l$?Cx:n8"$N$?$a$N<jB3$-$K=>$$(B | 
| 458 | Internet $BI8=`$r3+H/$9$kL\E*$KI,MW$J>l9g!"$"$k$$$O1Q8l0J30$N8@8l$KK]Lu$9$k$N$KI,MW$J>l9g$r=|$/!#(B | 
| 459 | </p> | 
| 460 | </div> | 
| 461 | </div> | 
| 462 | <div class="rfc-t"> | 
| 463 | <div class="t-pair t-hide-no"> | 
| 464 | <p class="t-l-en" xml:lang="en"> | 
| 465 | The limited permissions granted above are perpetual and will | 
| 466 | not be revoked by the Internet Society or its successors or | 
| 467 | assigns. | 
| 468 | </p> | 
| 469 | <p class="t-l-ja" xml:lang="ja"> | 
| 470 | $B>e5-$GG'$a$?$3$N@)8BIU$-5vBz$O915WE*$J$b$N$G$"$j!"(B | 
| 471 | Internet Society $B$b$7$/$O$=$N8e7Q<T$b$7$/$O$=$N>yEO<T$K$h$jGK4~$5$l$k$3$H$O$J$$!#(B | 
| 472 | </p> | 
| 473 | </div> | 
| 474 | </div> | 
| 475 | <div class="rfc-t"> | 
| 476 | <div class="t-pair t-hide-no"> | 
| 477 | <p class="t-l-en" xml:lang="en"> | 
| 478 | This document and the information contained herein is provided | 
| 479 | on an $B!H(B<strong>AS IS</strong>$B!I(B basis and | 
| 480 | <strong>THE INTERNET SOCIETY AND THE INTERNET ENGINEERING | 
| 481 | TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, | 
| 482 | INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF | 
| 483 | THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY | 
| 484 | IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR | 
| 485 | A PARTICULAR PURPOSE</strong>. | 
| 486 | </p> | 
| 487 | <p class="t-l-ja" xml:lang="ja"> | 
| 488 | $B$3$NJ8=q5Z$S$3$3$K4^$^$l$k>pJs$O!V(B<strong>$B8=>uM-;Q(B</strong>$B!W$GDs6!$5$l!"(B | 
| 489 | <strong>Internet Society $B$*$h$S(B | 
| 490 | <a href="http://www.ietf.org/">Internet Engineering Task Force | 
| 491 | (Internet $B5;=QFCJLD4::0Q0w2q(B)</a> | 
| 492 | $B$O$3$3$K4^$^$l$k>pJs$N;HMQ$,$$$+$J$k8"Mx$r$b?/32$7$J$$$H$$$&J]>Z$^$?$O;T>l@-$"$k$$$OFCDjL\E*$X$NE,Ev@-$K$D$$$F$N0EL[E*J]>Z$r4^$a$F$3$l$K8BDj$5$l$J$$!"L@<($"$k$$$O0E<($K$h$k!"0l@Z$NJ]>Z$rH]G'$9$k(B</strong>$B!#(B | 
| 493 | </p> | 
| 494 | </div> | 
| 495 | </div> | 
| 496 | <ins class="t-note t-l-ja" xml:lang="ja"> | 
| 497 | <p class="rfc-t"> | 
| 498 | (<span class="t-note-title">$BLuCm(B:</span> | 
| 499 | $B@5<0$JCx:n8"@<L@$O1Q8l$N86J8$N$_$G$"$j!"Lu<T$O0l@Z$NJ]>Z(B | 
| 500 | ($BK]LuJ8$,86J8$H87L)$K0lCW$7$F$$$k$+$r4^$`$,!"$3$l$K8BDj$5$l$J$$!#(B) | 
| 501 | $B$r(B<strong title="NOT">$B$7$J$$(B</strong>$B!#(B<a href="#rfc-t-copyright">$BLuJ8$K$D$$$F$NCx:n8"@<L@(B</a>$B$b;2>H$;$h!#(B) | 
| 502 | </p> | 
| 503 | </ins> | 
| 504 | </div> | 
| 505 |  | 
| 506 | <div id="rfc-acknowledgement-editor" class="rfc-section"> | 
| 507 | <div class="t-heading t-pair"> | 
| 508 | <h1 xml:lang="en" class="t-l-en">Acknowledgement</h1> | 
| 509 | <h1 xml:lang="ja" class="t-l-ja">$B<U<-(B</h1> | 
| 510 | </div> | 
| 511 | <div class="rfc-t"> | 
| 512 | <div class="t-pair"> | 
| 513 | <p class="t-l-en" xml:lang="en"> | 
| 514 | Funding for the | 
| 515 | <a href="http://www.rfceditor.org/">RFC editor</a> | 
| 516 | function is currently provided by the | 
| 517 | <a href="http://www.isoc.org/">Internet Society</a>. | 
| 518 | </p> | 
| 519 | <p class="t-l-ja" xml:lang="ja"> | 
| 520 | <a href="http://www.rfceditor.org/" xml:lang="en">RFC | 
| 521 | $BJT=8<T(B</a>$B6HL3$N;q6b1g=u$O8=:_(B | 
| 522 | <a href="http://www.isoc.org/">Internet Society</a> | 
| 523 | $B$K$h$j9T$o$l$F$$$^$9!#(B | 
| 524 | </p> | 
| 525 | </div> | 
| 526 | </div> | 
| 527 | </div> | 
| 528 | <ins id="rfc-translators-note" class="t-note t-l-ja" xml:lang="ja"> | 
| 529 | <div class="rfc-section" id="t-change"> | 
| 530 | <h1>$BK]Lu$NJQ99MzNr(B</h1> | 
| 531 | <dl> | 
| 532 | <dt>2002-05-12 <a href="mailto:w@suika.fam.cx" title="$BEE;R%a%$%k(B: <w@suika.fam.cx>">$B$o$+$P(B</a> | 
| 533 | </dt> | 
| 534 | <dd> | 
| 535 | <ul> | 
| 536 | <li>$BF|K\8l$KK]Lu!#(B</li> | 
| 537 | </ul> | 
| 538 | </dd> | 
| 539 | <dt>2002-05-26 <a href="mailto:w@suika.fam.cx" title="$BEE;R%a%$%k(B: <w@suika.fam.cx>">$B$o$+$P(B</a> | 
| 540 | </dt> | 
| 541 | <dd> | 
| 542 | <ul> | 
| 543 | <li> | 
| 544 | <a href="http://suika.fam.cx/uri-res/N2L?urn:ietf:rfc:2629" title="RFC 2629">RFC 2629</a> $B$G%^!<%/IU$1!#(B</li> | 
| 545 | </ul> | 
| 546 | </dd> | 
| 547 | </dl> | 
| 548 | </div> | 
| 549 | <div class="rfc-section" id="rfc-t-copyright"> | 
| 550 | <h1>$BLuJ8$K$D$$$F$NCx:n8"@<L@(B</h1> | 
| 551 | <p> | 
| 552 | <a href="#rfc-copyright">$B86J8$NCx:n8"@<L@(B</a>$B$,!"LuJ8$K$D$$$F$bF1MM$KE,MQ$5$l$^$9!#(B</p> | 
| 553 | <p>$B$^$?!"2~Lu$=$NB>$N86J8$NCx:n8"@<L@$KH?$7$J$$HO0O$K$*$1$k2~JQ$O!"0l@Z$N5v2DL5$/9T$C$F9=$$$^$;$s!#(B</p> | 
| 554 | </div> | 
| 555 | </ins> | 
| 556 | </body> | 
| 557 | </html> |