Internet Engineering Task Force (IETF) A. Hutton
Request for Comments: 7639 Unify
Category: Standards Track J. Uberti
ISSN: 2070-1721 Google
M. Thomson
Mozilla
August 2015
The ALPN HTTP Header Field
Hutton, et al. Standards Track [Page 1]
RFC 7639 The ALPN Header August 2015
Table of Contents
1. Introduction
The HTTP CONNECT method (Section 4.3.6 of [RFC7231]) requests that the recipient establish a tunnel to the identified origin server and thereafter forward packets, in both directions, until the tunnel is closed. Such tunnels are commonly used to create end-to-end virtual connections through one or more proxies.
Hutton, et al. Standards Track [Page 2]
RFC 7639 The ALPN Header August 2015 1.1. Requirements LanguageThe key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in RFC 2119 [RFC2119].
2. The ALPN HTTP Header Field
Clients include the ALPN header field in an HTTP CONNECT request to indicate the application-layer protocol that a client intends to use within the tunnel, or a set of protocols that might be used within the tunnel.
2.1. Header Field Values
Valid values for the protocol field are taken from the "Application- Layer Protocol Negotiation (ALPN) Protocol ID" registry [ALPN-IDS] established by [RFC7301].
2.2. Syntax
The ABNF (Augmented Backus-Naur Form) syntax for the ALPN header field value is given below. It uses the syntax defined in Section 1.2 of [RFC7230].
Hutton, et al. Standards Track [Page 3]
RFC 7639 The ALPN Header August 2015
CONNECT www.example.com HTTP/1.1 Host: www.example.com ALPN: h2, http%2F1.1
2.3. Usage
When used in the ALPN header field, an ALPN identifier is used to identify an entire application protocol stack, not a single protocol layer or component.
3. IANA Considerations
HTTP header fields are registered within the "Permanent Message Header Field Names" registry maintained by IANA [MSG-HDRS]. This document defines and registers the ALPN header field, according to [RFC3864] as follows: Header Field Name: ALPN
Hutton, et al. Standards Track [Page 4]
RFC 7639 The ALPN Header August 2015
Protocol: http
4. Security Considerations
In case of using HTTP CONNECT to a TURN (Traversal Using Relays around NAT, [RFC5766]) server, the security considerations of Section 4.3.6 of [RFC7231] apply. It states that there "are significant risks in establishing a tunnel to arbitrary servers, particularly when the destination is a well-known or reserved TCP port that is not intended for Web traffic. ... Proxies that support CONNECT SHOULD restrict its use to a limited set of known ports or a configurable whitelist of safe request targets."
Hutton, et al. Standards Track [Page 5]
RFC 7639 The ALPN Header August 2015 5. References 5.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
5.2. Informative References
[ALPN-IDS] IANA, "Application-Layer Protocol Negotiation (ALPN)
Hutton, et al. Standards Track [Page 6]
RFC 7639 The ALPN Header August 2015
[RFC5246] Dierks, T. and E. Rescorla, "The Transport Layer Security