Skip to content

WebIDs MUST use a secure protocol #76

@matthieubosquet

Description

@matthieubosquet

All resources used in the context of Solid Authentication and Authorization MUST use a secure protocol.

Namely, a WebID used for Authentication MUST use the https protocol. That is true of both client and user WebIDs.

Currently, the specification states: "a WebID is a HTTP URI". I couldn't find any specific requirements about security in transit.

I appreciate that it seems a bit like stating the obvious, but I reckon it is fundamentally important enough to require an extension of section 3, probably with a 3.2 Encryption of WebIDs in transit.

See also: https://www.ncsc.gov.uk/collection/cloud-security/implementing-the-cloud-security-principles/data-in-transit-protection

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions