As per Relevance of the word copyright, we have this rfc below:
Network Working Group E.
Requests for Comments: 2659 RTFM, Inc
Category: Experimental A.
Terisa Systems, Inc
August 1999
Security Extensions For
Status of this
This memo defines an Experimental Protocol for the
community. It does not specify an Internet standard of any kind
Discussion and suggestions for improvement are requested
Distribution of this memo is unlimited
Copyright
Copyright (C) The Internet Society (1999). All Rights Reserved
This memo describes a syntax for embedding S-HTTP
parameters in HTML documents. S-HTTP, as described by RFC 2660,
contains the concept of negotiation headers which reflect
potential receiver of a message's preferences as to which crypto
graphic enhancements should be applied to the message. This
describes a syntax for binding these negotiation parameters to
anchors
1.
2. Anchor
We define the following new anchor (and form submission) attributes
DN -- The distinguished name of the principal for whom
request should be encrypted when dereferencing the anchor's url
This need not be specified, but failure to do so runs the
that the client will be unable to determine the DN and
will be unable to encrypt. This should be specified in the
of RFC1485, using SGML quoting conventions as needed
NONCE -- A free-format string (appropriately SGML quoted)
is to be included in a SHTTP-Nonce: header (after SGML
is removed) when the anchor is dereferenced
CRYPTOPTS -- Cryptographic option information as described
Rescorla & Schiffman Experimental [Page 1]
RFC 2659 Security Extensions For HTML August 1999
[SHTTP]. Specifically, the production
2.1. CERTS
A new CERTS HTML element is defined, which carries a (not
related) group of certificates provided as advisory data. The
contents are not intended to be displayed to the user.
groups may be provided appropriate for either PEM or PKCS-7
implementations. Such certificates are supplied in the HTML
for the convenience of the recipient, who might otherwise be
to retrieve the certificate (chain) corresponding to a DN
in an anchor
The format should be the same as that of the 'Certificate-Info
header line, of [SHTTP] except that the specifier
be provided as the FMT attribute in the tag
Multiple CERTS elements are permitted; it is suggested that
elements themselves be included in the HTML document's HEAD
(in the hope that the data will not be displayed by S-HTTP
but HTML compliant browsers.)
2.2. CRYPTOPTS
Cryptopts may also be broken out into an element and referred to
anchors by name. The NAME attribute specifies the name by which
element may be referred to in a CRYPTOPTS attribute in an anchor
Names must have a # as the leading character
2.3. HTML
An example of cryptographic data embedded in an anchor, proceeded
a certificate group is provided below. Note the SGML quoting
used to supply embedded quotation marks
MIAGCSqGSIb3DQEHAqCAMIACAQExADCABgkqhkiG9w0
IIBrTCCAUkCAgC2MA0GCSqGSIb3DQEBAgUAME0
gYDVQQKExdSU0EgRGF0YSBTZWN1cml0eSwgSW5jLjEcMBoGA1
29uYSBDZXJ0aWZpY2F0ZTAeFw05NDA0MDkwMDUwMzdaFw05NDA4MDIxODM4
TdaMGcxCzAJBgNVBAYTAlVTMSAwHgYDVQQKExdSU0EgRGF0YSBTZWN1cml0
SwgSW5jLjEcMBoGA1UECxMTUGVyc29uYSBDZXJ0aWZpY2F0ZTEYMBYGA1
xMPU2V0ZWMgQXN0cm9ub215MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAMy8
cW7RMrB4sTdQ8Nmb2DFmJmkWn+el+NdeamIDElX/qw9mIQu4xNj1
zPvA0OtMKhy6+bkrlyMEU8CAwEAATANBgkqhkiG9w0BAQIFAANPAAYn7
rhiIL4wnP8nGzUisGSpsFsF4/7z2P2wqne6Qk8Cg/Dstu3RyaN78vAMGP8d
2H5+Ndfhi2mRp4YHiGHz0HlK6VbPfnyvS2
gkqhkiG9w0BAQIFADBfMQswCQYDVQQGEwJVUzEgMB4GA1
Rescorla & Schiffman Experimental [Page 2]
RFC 2659 Security Extensions For HTML August 1999
GEgU2VjdXJpdHksIEluYy4xLjAsBgNVBAsTJUxvdyBBc3N1cmFuY2UgQ2
GlmaWNhdGlvbiBBdXRob3JpdHkwHhcNOTQwMTA3MDAwMDAwWhcNOTYwMTA3
jM1OTU5WjBNMQswCQYDVQQGEwJVUzEgMB4GA1UEChMXUlNBIERhdGEgU2
XJpdHksIEluYy4xHDAaBgNVBAsTE1BlcnNvbmEgQ2
gkqhkiG9w0BAQEFAANYADBVAk4GqghQDa9Xi/2zAdYEqJVIcYhlLN1FpI9
Q1m6zZ39PYXK8Uhoj0Es7kWRv8hC04vqkOKwndWbzVtvoHQOmP8nOkkuBi+
QvgFoRcgOUCAwEAATANBgkqhkiG9w0BAQIFAANhAD/5Uo7xDdp49oZm9
PhZcW1e+nojLvHXWAU/CBkwfcR+FSf4hQ5eFu1AjYv6Wqf430Xe9Et5+
Tiq4LnwgTdA8xQX4elJz9QzQobkE3XVOjVAtCFcmiin80RB8
AAAAA==
DN="CN=Setec Astronomy, OU=Persona Certificate
O="RSA Data Security, Inc.", C=US
CRYPTOPTS="SHTTP-Privacy-Enhancements: recv-refused=encrypt
SHTTP-Signature-Algorithms: recv-required=NIST-DSS
HREF="shttp://research.nsa.gov/skipjack-holes.html">
Don't read this.
3. Security
This entire document is about security
4. Authors'
Eric
RTFM, Inc
30 Newell Road, #16
East Palo Alto, CA 94303
Phone: (650) 328-8631
EMail: ekr@rtfm.
Allan M.
SPYRUS/
5303 Betsy Ross
Santa Clara, CA 95054
Phone: (408) 327-1901
EMail: ams@terisa.
5.
[SHTTP] Rescorla, E. and A. Schiffman, "The Secure HyperText
Protocol", RFC 2660, August 1999.
Rescorla & Schiffman Experimental [Page 3]
RFC 2659 Security Extensions For HTML August 1999
6. Full Copyright
Copyright (C) The Internet Society (1999). All Rights Reserved
This document and translations of it may be copied and furnished
others, and derivative works that comment on or otherwise explain
or assist in its implementation may be prepared, copied,
and distributed, in whole or in part, without restriction of
kind, provided that the above copyright notice and this paragraph
included on all such copies and derivative works. However,
document itself may not be modified in any way, such as by
the copyright notice or references to the Internet Society or
Internet organizations, except as needed for the purpose
developing Internet standards in which case the procedures
copyrights defined in the Internet Standards process must
followed, or as required to translate it into languages other
English
The limited permissions granted above are perpetual and will not
revoked by the Internet Society or its successors or assigns
This document and the information contained herein is provided on
"AS IS" basis and THE INTERNET SOCIETY AND THE INTERNET
TASK FORCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED,
BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
HEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
Funding for the RFC Editor function is currently provided by
Internet Society
Rescorla & Schiffman Experimental [Page 4]
if you see any problems within the linking, don't worry be happy,
this is version 0.1 of the Relevance System and you gotta expect some crappy subroutines sometimes,
just be content we did not write this in Java, which would have made this "bigger and better" HAHAHHA.
RFC documents can be found at I.E.T.F.
Relevance System Copyright © 2002 Spectrum WorldResearch
other technical nosh by ServerMasters Corporation
collaboration of BobX