# validate-9110-qualifier tool: validate_statement args: {"rfc":9110,"statement":"The origin server generates a Date header field even though it has no clock."} --- json --- { "rfc": 9110, "statement": "The origin server generates a Date header field even though it has no clock.", "analysis": { "detectedLevel": null, "detectedSubject": "server" }, "isValid": null, "_verdictNote": "isValid is null: requirement R-6.6.1-4 turns on \"without\", a word the statement does not use, so whether they describe the same case cannot be decided. This is not a statement of compliance.", "matchingRequirements": [ { "id": "R-6.6.1-2", "level": "MUST", "text": "An origin server with a clock (as defined in Section 5.6.7) MUST generate a Date header field in all 2xx (Successful), 3xx (Redirection), and 4xx (Client Error) responses, and MAY generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses.", "section": "6.6.1", "sectionTitle": "Date", "fullContext": "An origin server with a clock (as defined in Section 5.6.7) MUST generate a Date header field in all 2xx (Successful), 3xx (Redirection), and 4xx (Client Error) responses, and MAY generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses.", "action": "generate a Date header field in all 2xx (Successful), 3xx (Redirection), and 4xx (Client Error) responses, and MAY generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses", "_matchScore": 17, "_matchedKeywords": [ "origin", "server", "generates", "date", "header", "field", "clock" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-6.6.1-3", "level": "MAY", "text": "An origin server with a clock (as defined in Section 5.6.7) MUST generate a Date header field in all 2xx (Successful), 3xx (Redirection), and 4xx (Client Error) responses, and MAY generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses.", "section": "6.6.1", "sectionTitle": "Date", "fullContext": "An origin server with a clock (as defined in Section 5.6.7) MUST generate a Date header field in all 2xx (Successful), 3xx (Redirection), and 4xx (Client Error) responses, and MAY generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses.", "action": "generate a Date header field in 1xx (Informational) and 5xx (Server Error) responses", "_matchScore": 17, "_matchedKeywords": [ "origin", "server", "generates", "date", "header", "field", "clock" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-6.6.1-4", "level": "MUST NOT", "text": "An origin server without a clock MUST NOT generate a Date header field.", "section": "6.6.1", "sectionTitle": "Date", "fullContext": "An origin server without a clock MUST NOT generate a Date header field.", "subject": "clock", "action": "generate a Date header field", "_matchScore": 17, "_matchedKeywords": [ "origin", "server", "generates", "date", "header", "field", "clock" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-10.2.1-1", "level": "MUST", "text": "An origin server MUST generate an Allow header field in a 405 (Method Not Allowed) response and MAY do so in any other response.", "section": "10.2.1", "sectionTitle": "Allow", "fullContext": "The actual set of allowed methods is defined by the origin server at the time of each request. An origin server MUST generate an Allow header field in a 405 (Method Not Allowed) response and MAY do so in any other response. An empty Allow field value indicates that the resource allows no methods, which might occur in a 405 response if the resource has been temporarily disabled by configuration.", "subject": "origin server", "action": "generate an Allow header field in a 405 (Method Not Allowed) response and MAY do so in any other response", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-10.2.1-2", "level": "MAY", "text": "An origin server MUST generate an Allow header field in a 405 (Method Not Allowed) response and MAY do so in any other response.", "section": "10.2.1", "sectionTitle": "Allow", "fullContext": "The actual set of allowed methods is defined by the origin server at the time of each request. An origin server MUST generate an Allow header field in a 405 (Method Not Allowed) response and MAY do so in any other response. An empty Allow field value indicates that the resource allows no methods, which might occur in a 405 response if the resource has been temporarily disabled by configuration.", "subject": "origin server", "action": "do so in any other response", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-10.2.4-1", "level": "MAY", "text": "An origin server MAY generate a Server header field in its responses.", "section": "10.2.4", "sectionTitle": "Server", "fullContext": "The \"Server\" header field contains information about the software used by the origin server to handle the request, which is often used by clients to help identify the scope of reported interoperability problems, to work around or tailor requests to avoid particular server limitations, and for analytics regarding server or operating system use. An origin server MAY generate a Server header field in its responses.", "subject": "origin server", "action": "generate a Server header field in its responses", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-10.2.4-2", "level": "SHOULD NOT", "text": "An origin server SHOULD NOT generate a Server header field containing needlessly fine-grained detail and SHOULD limit the addition of subproducts by third parties.", "section": "10.2.4", "sectionTitle": "Server", "fullContext": "An origin server SHOULD NOT generate a Server header field containing needlessly fine-grained detail and SHOULD limit the addition of subproducts by third parties. Overly long and detailed Server field values increase response latency and potentially reveal internal implementation details that might make it (slightly) easier for attackers to find and exploit known security holes.", "subject": "origin server", "action": "generate a Server header field containing needlessly fine-grained detail and SHOULD limit the addition of subproducts by third parties", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-10.2.4-3", "level": "SHOULD", "text": "An origin server SHOULD NOT generate a Server header field containing needlessly fine-grained detail and SHOULD limit the addition of subproducts by third parties.", "section": "10.2.4", "sectionTitle": "Server", "fullContext": "An origin server SHOULD NOT generate a Server header field containing needlessly fine-grained detail and SHOULD limit the addition of subproducts by third parties. Overly long and detailed Server field values increase response latency and potentially reveal internal implementation details that might make it (slightly) easier for attackers to find and exploit known security holes.", "subject": "origin server", "action": "limit the addition of subproducts by third parties", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-12.5.5-2", "level": "MUST NOT", "text": "To inform cache recipients that they MUST NOT use this response to satisfy a later request unless the later request has the same values for the listed header fields as the original request (Section 4.1 of [CACHING]) or reuse of the response has been validated by the origin server.", "section": "12.5.5", "sectionTitle": "Vary", "fullContext": "To inform cache recipients that they MUST NOT use this response to satisfy a later request unless the later request has the same values for the listed header fields as the original request (Section 4.1 of [CACHING]) or reuse of the response has been validated by the origin server. In other words, Vary expands the cache key required to match a new request to the stored cache entry.", "exception": "the later request has the same values for the listed header fields as the original request (Section 4.1 of [CACHING]) or reuse of the response has been validated by the origin server", "action": "use this response to satisfy a later request unless the later request has the same values for the listed header fields as the original request (Section 4.1 of [CACHING]) or reuse of the response has been validated by the origin server", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "date", "header", "field" ], "_subjectMatch": true, "_levelMatch": false }, { "id": "R-12.5.5-3", "level": "SHOULD", "text": "An origin server SHOULD generate a Vary header field on a cacheable response when it wishes that response to be selectively reused for subsequent requests.", "section": "12.5.5", "sectionTitle": "Vary", "fullContext": "An origin server SHOULD generate a Vary header field on a cacheable response when it wishes that response to be selectively reused for subsequent requests. Generally, that is the case when the response content has been tailored to better fit the preferences expressed by those selecting header fields, such as when an origin server has selected the response's language based on the request's Accept-Language header field.", "subject": "origin server", "condition": "it wishes that response to be selectively reused for subsequent requests", "action": "generate a Vary header field on a cacheable response when it wishes that response to be selectively reused for subsequent requests", "_matchScore": 15, "_matchedKeywords": [ "origin", "server", "generates", "header", "field" ], "_subjectMatch": true, "_levelMatch": false } ], "conflicts": [], "suggestions": [ "Cannot judge: requirement R-6.6.1-4 turns on \"without\", a word the statement does not use. Read that requirement and decide whether the statement means the same case." ], "_source": "xml" }