Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft

Magnus Westerlund <magnus.westerlund@ericsson.com> Wed, 01 June 2011 08:09 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D3C9E075F for <avt@ietfa.amsl.com>; Wed, 1 Jun 2011 01:09:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.28
X-Spam-Level:
X-Spam-Status: No, score=-106.28 tagged_above=-999 required=5 tests=[AWL=0.319, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ueoLA+7pf4fS for <avt@ietfa.amsl.com>; Wed, 1 Jun 2011 01:09:50 -0700 (PDT)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by ietfa.amsl.com (Postfix) with ESMTP id D46BAE0750 for <avt@ietf.org>; Wed, 1 Jun 2011 01:09:49 -0700 (PDT)
X-AuditID: c1b4fb3d-b7c17ae00000262e-be-4de5f3cc14b9
Received: from esessmw0184.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id 69.AC.09774.CC3F5ED4; Wed, 1 Jun 2011 10:09:48 +0200 (CEST)
Received: from [127.0.0.1] (153.88.115.8) by esessmw0184.eemea.ericsson.se (153.88.115.82) with Microsoft SMTP Server id 8.3.137.0; Wed, 1 Jun 2011 10:09:47 +0200
Message-ID: <4DE5F3CB.80304@ericsson.com>
Date: Wed, 01 Jun 2011 10:09:47 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.17) Gecko/20110414 Thunderbird/3.1.10
MIME-Version: 1.0
To: "Igoe, Kevin M." <kmigoe@nsa.gov>
References: <4FD125153A070D45BC87645D3B880288025A13CACB@IMCMBX3.MITRE.ORG> <4DE4AC77.9050501@ericsson.com> <80F9AC969A517A4DA0DE3E7CF74CC1BB425B19@MSIS-GH1-UEA06.corp.nsa.gov>
In-Reply-To: <80F9AC969A517A4DA0DE3E7CF74CC1BB425B19@MSIS-GH1-UEA06.corp.nsa.gov>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-Brightmail-Tracker: AAAAAA==
Cc: "avt@ietf.org" <avt@ietf.org>
Subject: Re: [AVTCORE] Suite B Profile for DTLS-SRTP Internet-Draft
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Jun 2011 08:09:52 -0000

On 2011-05-31 14:24, Igoe, Kevin M. wrote:
> Magnus:
> 
>   Thanks for your input.  We'll put this under avtcore per your request.
> As to allowing keying methods other than DTLS, we have no objections
> (obviously) to non-Suite B implementations using them, but in an
> effort to maximize interoperability betwixt Suite B SRTP implementations
> policy dictates that only DTLS keying will be allowed in Suite B mode.
> If another keying methods is used, it is by definition not Suite B compliant.

Ok, so SuiteB also contains beyond the crypto algorithms also usage
rules that affects key management. Are these rulse also forbidding use
cases like Broadcast or multicast where using DTLS-SRTP is in fact
impossible?

> 
> If you think it would be helpful, we could mention the existence of the MIKEY 
> and Security description keying mechanisms, but only with the caveat that their 
> use is forbidden when running in Suite B mode.

My immediate reaction is if one can define profiles that are not SuiteB
but use the same encryption and authentication algorithm so they are bit
compatible, but not policy compatible?

Independent I think you need to make it clear in the document that
SuiteB does contain these policy rules.

Cheers

Magnus Westerlund

----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB                | Phone  +46 10 7148287
Färögatan 6                | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------