Skip to content

Please clarify expected client behavior in the face of HTTP 301 and 302 redirection

Hans-Christoph Steiner notes that dirmngr doesn't accept HTTP redirections when performing wkd. I believe dirmngr does follow redirections, but only limited in some sort of scope (i don't remember what the limitations are).

If clients are expected to not follow HTTP redirection, this should be documented in the standard. If clients may or may not follow HTTP redirection, this should also probably be documented in the standard, so that domains that deploy WKD know of the risks when deploying the directory using redirection.