|
Preamble
2. Summary
|
2. SummaryThis specification describes a concrete syntax for a public key authentication scheme for HTTP transactions. It provides a minimal HTTP extension for mutual authentication and message origin authentication, via the integrity protection of a defined set of HTTP message headers. It offers message sequence integrity, forward secrecy, and optionally content integrity and content ciphering. It is intended for application in situations where credential-based schemes are inappropriate for architectural reasons or are considered too weak, and also where message-layer and/or application-layer security requirements are not fulfilled by transport-layer or network-layer security protocols. It is not intended as a substitute for lower- or higher-layer security protocols, and indeed may be found to usefully coexist with these. |