Skip to content

enygren/draft-nygren-httpbis-http11-request-binding

Repository files navigation

HTTP/1.1 Request Smuggling Defense using Cryptographic Request Binding

This is the working area for the individual Internet-Draft, "HTTP/1.1 Request Smuggling Defense using Cryptographic Request Binding".

HTTP/1.1 Request Binding adds new hop-by-hop request headers that are cryptographically bound to requests and responses. The keys used are negotiated out-of-band from the HTTP datastream (such as via TLS Exporters). These headers allow endpoints to detect and mitigate desynchronization attacks, such as HTTP Request Smuggling, that exist due to datastream handling differences.

Contributing

See the guidelines for contributions.

The contributing file also has tips on how to make contributions, if you don't already know how to do that.

Command Line Usage

Formatted text and HTML versions of the draft can be built using make.

$ make

Command line usage requires that you have the necessary software installed. See the instructions.

About

IETF Draft: HTTP/1.1 Request Smuggling Defense using Cryptographic Request Binding

Resources

License

Contributing

Stars

Watchers

Forks

Packages

 
 
 

Contributors