ietf-nntp TLS response codes

Clive D.W. Feather clive at demon.net
Thu Mar 20 06:21:13 PST 2003


Russ Allbery said:
> For using STARTTLS after encryption is already active, we're removing
> STARTTLS from the available extensions after it successfully completes,
> right?  That would indicate that 500 is the right error code to use; after
> all, it's no longer a recognized command.

Disagree, and I think this sends the wrong message. Surely it's 502:

    If the client is not authorized to use the specified facility
    when the server is in its current state, the response code 
    502 MUST be returned.

-- 
Clive D.W. Feather  | Work:  <clive at demon.net>   | Tel:  +44 20 8371 1138
Internet Expert     | Home:  <clive at davros.org>  | Fax:  +44 870 051 9937
Demon Internet      | WWW: http://www.davros.org | Mobile: +44 7973 377646
Thus plc            |                            |



More information about the ietf-nntp mailing list