Il ne faut pas résumer le débat à ce troll. Le message laisse entendre qu'il y a un consensus sur ce point ce qui est loin d'être le cas. C'est du lobbying, ni plus ni moins.
Même d'autres gens présent à cette réunion ne sont pas d'accord sur l'interprétation.
>>> 745 4) Requre secure underlying protocol for HTTP/2.0 (at least in web browsing)
>>> 746
>>> 747 [ weaker for can't live with ]
>>
>> Are you saying that 4) == C), and that 4) was about using https only?
>
> In a nutshell, yes.
I'm still confused. What you say implies that http: URIs will not use
HTTP/2. We did *not* discuss this as option 4.
Pour l'heure on peut dire que les gens qui font des navigateurs sont plutôt pour utiliser TLS systématiquement et que les gens qui font des proxys sont carrément contre.
> To be clear - we will still define how to use HTTP/2.0 with http:// URIs, because in some use cases, an implementer may make an informed choice to use the protocol without encryption. However, for the common case -- browsing the open Web -- you'll need to use https:// URIs and if you want to use the newest version of HTTP.
For the record, I strongly believe that support for unencrypted HTTP/2.0 is still needed and useful, particularly when you are routing it over an already "secure" channel to a resource-constrained device. And there will likely be practical real-life limitations of what browser vendors choose to implement, i.e., no HTTP/2.0 support for http:// URIs. However, I honestly don’t see how this WG can actually enforce/mandate https:// and still allow http:// URIs. So long as unencrypted URIs are supported by HTTP/2.0, the best you can do is make security recommendations since TLS is not REQUIRED (in the RFC 2119 sense) for the open web.
I also believe that HTTP/1.x has been so successful because of its ease (and freedom) of implementation. But IMHO restricting its use to https:// will only limit its use/deployment to sites/providers that can afford to deploy it and prevent HTTP/2.0 from replacing HTTP/1.1 in the long run.
Bref s'il y a un consensus qui se dessine, il serait plutôt contre.
# La situation est plus compliquée que ça.
Posté par Joris Dedieu (site web personnel) . En réponse au journal Généralisation du mode sécurisé dans HTTP 2.0 ?. Évalué à 4.
Il ne faut pas résumer le débat à ce troll. Le message laisse entendre qu'il y a un consensus sur ce point ce qui est loin d'être le cas. C'est du lobbying, ni plus ni moins.
Même d'autres gens présent à cette réunion ne sont pas d'accord sur l'interprétation.
Pour l'heure on peut dire que les gens qui font des navigateurs sont plutôt pour utiliser TLS systématiquement et que les gens qui font des proxys sont carrément contre.
Bref s'il y a un consensus qui se dessine, il serait plutôt contre.