IƱaki Baz Castillo writes:
This is, the entire path *until* the proxy responsible for the domain in the RURI must be secure (TLS) but it's not required (local policy) that the destination proxy dellivers the request to the destination user using TLS.
if i remember correctly, ietf has revised the above to actually require use o tls end to end, but who cares anyway, because that organization has not saying in real life anymore.
-- juha