Return-Path: X-Original-To: apmail-hc-httpclient-users-archive@www.apache.org Delivered-To: apmail-hc-httpclient-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 4496717F23 for ; Thu, 5 Feb 2015 15:11:10 +0000 (UTC) Received: (qmail 83672 invoked by uid 500); 5 Feb 2015 15:11:10 -0000 Delivered-To: apmail-hc-httpclient-users-archive@hc.apache.org Received: (qmail 83616 invoked by uid 500); 5 Feb 2015 15:11:10 -0000 Mailing-List: contact httpclient-users-help@hc.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "HttpClient User Discussion" Delivered-To: mailing list httpclient-users@hc.apache.org Received: (qmail 83602 invoked by uid 99); 5 Feb 2015 15:11:09 -0000 Received: from mail-relay.apache.org (HELO mail-relay.apache.org) (140.211.11.15) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 05 Feb 2015 15:11:09 +0000 Received: from ubuntu (77-57-180-223.dclient.hispeed.ch [77.57.180.223]) by mail-relay.apache.org (ASF Mail Server at mail-relay.apache.org) with ESMTPSA id 3201B1A038C for ; Thu, 5 Feb 2015 15:11:08 +0000 (UTC) Message-ID: <1423149065.4240.10.camel@apache.org> Subject: Re: [ANNOUNCEMENT] HttpComponents Client 4.4 GA Released From: Oleg Kalnichevski To: HttpClient User Discussion Date: Thu, 05 Feb 2015 16:11:05 +0100 In-Reply-To: References: <1423146640.4240.6.camel@apache.org> Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.12.7-0ubuntu1 Mime-Version: 1.0 Content-Transfer-Encoding: 7bit On Thu, 2015-02-05 at 16:06 +0100, Christopher BROWN wrote: > Hello Oleg, > > Congratulations on the release. I have a quick question concerning one > item in the release notes, but don't have a suitable network to test it on. > > * Default SSL hostname verifier and default cookie policy now validate > > certificate identity and cookie domain of origin against the public > > suffix list maintained by Mozilla.org > > > > What happens if HTTP client is used in a network where "publicsuffix.org" > can't be reached? Sometimes, we have customers that apply excessive > restrictions on access to external networks, whilst still using HTTPS for > internal servers. Will it raise an exception? Will it slow down > connections? Can it be disabled if either of these two questions are in > fact problematic (it of course makes a lot of sense NOT to disable it). > > Thanks, > Christopher HC 4.4 ships with a local copy of the list. HC will make no outbound requests to publicsuffix.org. Oleg --------------------------------------------------------------------- To unsubscribe, e-mail: httpclient-users-unsubscribe@hc.apache.org For additional commands, e-mail: httpclient-users-help@hc.apache.org