Re: [AVT] Re: Changes in draft-ietf-avt-2833bis-13.txt

Colin Perkins <csp@csperkins.org> Tue, 09 May 2006 13:49 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1FdSaJ-0003Qc-SX; Tue, 09 May 2006 09:49:07 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1FdSaI-0003QR-Nq for avt@ietf.org; Tue, 09 May 2006 09:49:06 -0400
Received: from mr1.dcs.gla.ac.uk ([130.209.249.184]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FdSaH-0001Yq-9c for avt@ietf.org; Tue, 09 May 2006 09:49:06 -0400
Received: from mangole.dcs.gla.ac.uk ([130.209.247.112]:50987) by mr1.dcs.gla.ac.uk with esmtpsa (TLSv1:RC4-SHA:128) (Exim 4.42) id 1FdSaD-00019j-5g; Tue, 09 May 2006 14:49:01 +0100
In-Reply-To: <44609AEA.5060007@nortel.com>
References: <E1FRaAf-00045B-Mc@stiedprstage1.ietf.org> <09A1A16A-0717-4CA2-B046-6DF3E07EADB2@csperkins.org> <264B91EE-181F-4E7F-9A2F-B5837837AC33@csperkins.org> <446008DC.7020204@nortel.com> <Pine.WNT.4.62.0605091038160.244@CTO-LAPTOP.eu.rsa.net> <44605F43.9010301@ericsson.com> <44609AEA.5060007@nortel.com>
Mime-Version: 1.0 (Apple Message framework v749.3)
Content-Type: text/plain; charset="ISO-8859-1"; delsp="yes"; format="flowed"
Message-Id: <0E631FB4-C579-4BB4-8E74-8D7A3CC0DE5B@csperkins.org>
Content-Transfer-Encoding: quoted-printable
From: Colin Perkins <csp@csperkins.org>
Subject: Re: [AVT] Re: Changes in draft-ietf-avt-2833bis-13.txt
Date: Tue, 09 May 2006 14:49:01 +0100
To: Tom-PT Taylor <taylor@nortel.com>
X-Mailer: Apple Mail (2.749.3)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: c0bedb65cce30976f0bf60a0a39edea4
Cc: Cullen Jennings <fluffy@cisco.com>, Magnus Westerlund <magnus.westerlund@ericsson.com>, Pekka Nikander <pekka.nikander@nomadiclab.com>, IETF AVT WG <avt@ietf.org>, "Michael A. Patton" <map@map-ne.com>, magnus@rsasecurity.com, Sasha Vainshtein <Sasha@AXERRA.com>, Henning Schulzrinne <hgs@cs.columbia.edu>
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Audio/Video Transport Working Group <avt.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
Errors-To: avt-bounces@ietf.org

I agree with Magnus Westerlund: it makes sense to say one SHOULD  
implement SRTP, since it provides appropriate security for many  
environments, but we cannot absolutely mandate it, since there are  
valid uses of RTP where SRTP isn't the right security solution.

Colin




On 9 May 2006, at 14:36, Tom-PT Taylor wrote:
> Magnus Nyström is correct as far as my intent was concerned -- I  
> goofed. However, I think I'll keep my head down while the broader  
> issues are thrashed out. I do think, now that I've looked at it,  
> that the Security Considerations section of RFC 3550 could have  
> been more thoroughly developed, but as a member of the AVT WG, I  
> have to take some responsibility for that.
>
> Earlier in this thread Magnus W. mentioned draft-westerlund-avt-rtp- 
> howto-00. I'll try to contribute when that is reissued, to make  
> amends for my earlier neglect.
>
> Magnus Westerlund wrote:
>> Magnus Nyström wrote:
>>> Thanks for this, Tom.
>>>
>>> I have one comment. You write:
>>>
>>>> "To meet the need for protection both of confidentiality and  
>>>> integrity, this specification requires that compliant  
>>>> implementations also implement the Secure Real-time Transport  
>>>> Protocol (SRTP) [RFC3711].
>>>
>>> If this is a normative statement (and it looks like it), perhaps  
>>> it should be rephrased to:
>>>
>>> "To meet the need for protection both of confidentiality and  
>>> integrity, compliant implementations MUST also implement [or  
>>> support] the Secure Real-time Transport Protocol (SRTP) [RFC3711]."
>>>
>> Hi Magnus,
>> There is one problem with mandating SRTP as the security  
>> mechanism. It is not suitable for all deployment scenarios that  
>> RTP is used in. Due to this we have been very cautious to mandate.  
>> We gladly recommend SRTP as it works in most deployments. RTPs  
>> wide deployment potential do create an issue here.
>> I think we are getting to a situation where we might need to  
>> clarify the usage of security mechanism for RTP and for which  
>> cases they are suitable to adapt for different applications.
>> cheers
>> Magnus Westerlund
>> Multimedia Technologies, Ericsson Research EAB/TVA/A
>> --------------------------------------------------------------------- 
>> -
>> Ericsson AB                | Phone +46 8 4048287
>> Torshamsgatan 23           | Fax   +46 8 7575550
>> S-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
>
>
> _______________________________________________
> Audio/Video Transport Working Group
> avt@ietf.org
> https://www1.ietf.org/mailman/listinfo/avt


_______________________________________________
Audio/Video Transport Working Group
avt@ietf.org
https://www1.ietf.org/mailman/listinfo/avt