Cookie-based HTTP Authentication
draft-broyer-http-cookie-auth-00

Document Type Expired Internet-Draft (individual)
Last updated 2009-01-04
Stream (None)
Intended RFC status (None)
Formats
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at
https://www.ietf.org/archive/id/draft-broyer-http-cookie-auth-00.txt

Abstract

This document specifies an HTTP authentication scheme for use when credentials are validated by an out-of-band mechanism (not defined here) and later communicated to the server through the use of a cookie. Which out-of-band mechanism should be used, and how, is described by the 401 (Unauthorized) response body. It is common practice that this mechanism is an HTML form, sending the user's credentials with the use of an HTTP POST request to a tier URL which will set a cookie in response; though this document doesn't preclude the use of other mechanisms.

Authors

Thomas Broyer (t.broyer@ltgt.net)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)