Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

document why only "valid domain" format is allowed for "effective domain" #517

Closed
equalsJeffH opened this issue Aug 2, 2017 · 2 comments · Fixed by #975
Closed

document why only "valid domain" format is allowed for "effective domain" #517

equalsJeffH opened this issue Aug 2, 2017 · 2 comments · Fixed by #975

Comments

@equalsJeffH
Copy link
Contributor

the rationale is essentially the same as for HSTS, which is documented like so...

4.     HSTS Hosts are identified only via domain names -- explicit IP
       address identification of all forms is excluded.  This is for
       simplification and also is in recognition of various issues with
       using direct IP address identification in concert with PKI-based
       security.
@selfissued
Copy link
Contributor

On the 28-Feb-18, we asked whether #515 closed this. @equalsJeffH to investigate.

@equalsJeffH
Copy link
Contributor Author

This issue has two parts. PR #515 addressed the first part by making explicit that "IP address identification of all forms is excluded." (thx).

However, the rationale is not stated, e.g.:

This is for simplification and also is in recognition of various issues with using direct IP address identification in concert with PKI-based security.

..which we can simply add to the Notes pr #515 added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
3 participants