ietf-nntp TLS response codes

Russ Allbery rra at stanford.edu
Thu Mar 20 09:30:26 PST 2003


Clive D W Feather <clive at demon.net> writes:
> Russ Allbery said:

>> For using STARTTLS after encryption is already active, we're removing
>> STARTTLS from the available extensions after it successfully completes,
>> right?  That would indicate that 500 is the right error code to use;
>> after all, it's no longer a recognized command.

> Disagree, and I think this sends the wrong message. Surely it's 502:

>     If the client is not authorized to use the specified facility
>     when the server is in its current state, the response code 
>     502 MUST be returned.

Okay, yes, good point.  I agree, 502 would be better.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>



More information about the ietf-nntp mailing list