Skip to main content

An Architecture for Secure Content Delegation using HTTP

Document Type Expired Internet-Draft (individual)
Authors Martin Thomson , Goran Eriksson , Christer Holmberg
Last updated 2017-05-03 (Latest revision 2016-10-30)
Stream (None)
Intended RFC status (None)
Expired & archived
plain text xml htmlized pdfized bibtex
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)
This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at:


An architecture is described for content distribution using a secondary server that might be operated with reduced privileges. This architecture allows a primary server to delegate the responsibility for delivery of the payload of an HTTP response to a secondary server. The secondary server is unable to modify this content. The content is encrypted, which in some cases will prevent the secondary server from learning about the content.


Martin Thomson
Goran Eriksson
Christer Holmberg

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)