跳到主要内容

9.2. 资料性参考文献

9.2. 资料性参考文献​

下列参考文献提供背景信息与相关阅读材料, 不具有规范性.

[AWS-SIGv4]
           Amazon Simple Storage Service, "Authenticating Requests
           (AWS Signature Version 4)", March 2006,
           <https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-
           authenticating-requests.html>.

[BCP195]   Moriarty, K. and S. Farrell, "Deprecating TLS 1.0 and TLS
           1.1", BCP 195, RFC 8996, March 2021.

           Sheffer, Y., Saint-Andre, P., and T. Fossati,
           "Recommendations for Secure Use of Transport Layer
           Security (TLS) and Datagram Transport Layer Security
           (DTLS)", BCP 195, RFC 9325, November 2022.

           <https://www.rfc-editor.org/info/bcp195>

[CLIENT-CERT]
           Campbell, B. and M. Bishop, "Client-Cert HTTP Header
           Field", RFC 9440, DOI 10.17487/RFC9440, July 2023,
           <https://www.rfc-editor.org/info/rfc9440>.

[COOKIE]   Barth, A., "HTTP State Management Mechanism", RFC 6265,
           DOI 10.17487/RFC6265, April 2011,
           <https://www.rfc-editor.org/info/rfc6265>.

[DIGEST]   Polli, R. and L. Pardue, "Digest Fields", RFC 9530,
           DOI 10.17487/RFC9530, February 2024,
           <https://www.rfc-editor.org/info/rfc9530>.

[JACKSON2019]
           Jackson, D., Cremers, C., Cohn-Gordon, K., and R. Sasse,
           "Seems Legit: Automated Analysis of Subtle Attacks on
           Protocols that Use Signatures", CCS '19: Proceedings of
           the 2019 ACM SIGSAC Conference on Computer and
           Communications Security, pp. 2165-2180,
           DOI 10.1145/3319535.3339813, November 2019,
           <https://dl.acm.org/doi/10.1145/3319535.3339813>.

[JWS]      Jones, M., Bradley, J., and N. Sakimura, "JSON Web
           Signature (JWS)", RFC 7515, DOI 10.17487/RFC7515, May
           2015, <https://www.rfc-editor.org/info/rfc7515>.

[RFC7239]  Petersson, A. and M. Nilsson, "Forwarded HTTP Extension",
           RFC 7239, DOI 10.17487/RFC7239, June 2014,
           <https://www.rfc-editor.org/info/rfc7239>.

[RFC7468]  Josefsson, S. and S. Leonard, "Textual Encodings of PKIX,
           PKCS, and CMS Structures", RFC 7468, DOI 10.17487/RFC7468,
           April 2015, <https://www.rfc-editor.org/info/rfc7468>.

[RFC7807]  Nottingham, M. and E. Wilde, "Problem Details for HTTP
           APIs", RFC 7807, DOI 10.17487/RFC7807, March 2016,
           <https://www.rfc-editor.org/info/rfc7807>.

[RFC8126]  Cotton, M., Leiba, B., and T. Narten, "Guidelines for
           Writing an IANA Considerations Section in RFCs", BCP 26,
           RFC 8126, DOI 10.17487/RFC8126, June 2017,
           <https://www.rfc-editor.org/info/rfc8126>.

[RFC8792]  Watsen, K., Auerswald, E., Farrel, A., and Q. Wu,
           "Handling Long Lines in Content of Internet-Drafts and
           RFCs", RFC 8792, DOI 10.17487/RFC8792, June 2020,
           <https://www.rfc-editor.org/info/rfc8792>.

[RFC9457]  Nottingham, M., Wilde, E., and S. Dalal, "Problem Details
           for HTTP APIs", RFC 9457, DOI 10.17487/RFC9457, July 2023,
           <https://www.rfc-editor.org/info/rfc9457>.

[SIGNING-HTTP-MESSAGES]
           Cavage, M. and M. Sporny, "Signing HTTP Messages", Work in
           Progress, Internet-Draft, draft-cavage-http-signatures-12,
           21 October 2019, <https://datatracker.ietf.org/doc/html/
           draft-cavage-http-signatures-12>.

[SIGNING-HTTP-REQS-OAUTH]
           Richer, J., Ed., Bradley, J., and H. Tschofenig, "A Method
           for Signing HTTP Requests for OAuth", Work in Progress,
           Internet-Draft, draft-ietf-oauth-signed-http-request-03, 8
           August 2016, <https://datatracker.ietf.org/doc/html/draft-
           ietf-oauth-signed-http-request-03>.

[TLS]      Rescorla, E., "The Transport Layer Security (TLS) Protocol
           Version 1.3", RFC 8446, DOI 10.17487/RFC8446, August 2018,
           <https://www.rfc-editor.org/info/rfc8446>.