Re: [AVTCORE] Working group last call on draft-ietf-avtcore-srtp-aes-gcm-03

Jonathan Lennox <jonathan@vidyo.com> Tue, 27 November 2012 17:31 UTC

Return-Path: <jonathan@vidyo.com>
X-Original-To: avt@ietfa.amsl.com
Delivered-To: avt@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CDAAA21F8608 for <avt@ietfa.amsl.com>; Tue, 27 Nov 2012 09:31:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gMxsuhOFlGeD for <avt@ietfa.amsl.com>; Tue, 27 Nov 2012 09:31:33 -0800 (PST)
Received: from mxout.myoutlookonline.com (mxout.myoutlookonline.com [64.95.72.241]) by ietfa.amsl.com (Postfix) with ESMTP id 9887D21F8647 for <avt@ietf.org>; Tue, 27 Nov 2012 09:31:32 -0800 (PST)
Received: from mxout.myoutlookonline.com (localhost [127.0.0.1]) by mxout.myoutlookonline.com (Postfix) with ESMTP id DE7F18C0C28 for <avt@ietf.org>; Tue, 27 Nov 2012 12:31:31 -0500 (EST)
X-Virus-Scanned: by SpamTitan at mail.lan
Received: from HUB022.mail.lan (unknown [10.110.2.1]) (using TLSv1 with cipher RC4-MD5 (128/128 bits)) (No client certificate requested) by mxout.myoutlookonline.com (Postfix) with ESMTPS id 54FFE8BE2F4 for <avt@ietf.org>; Tue, 27 Nov 2012 12:31:06 -0500 (EST)
Received: from BE235.mail.lan ([10.110.32.235]) by HUB022.mail.lan ([10.110.17.22]) with mapi; Tue, 27 Nov 2012 12:30:49 -0500
From: Jonathan Lennox <jonathan@vidyo.com>
To: IETF AVTCore WG <avt@ietf.org>
Date: Tue, 27 Nov 2012 12:31:05 -0500
Thread-Topic: [AVTCORE] Working group last call on draft-ietf-avtcore-srtp-aes-gcm-03
Thread-Index: Ac3MwevKDV9SQEkUR6uil24H/A5mtw==
Message-ID: <C3759687E4991243A1A0BD44EAC823034DFAC1F62E@BE235.mail.lan>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [AVTCORE] Working group last call on draft-ietf-avtcore-srtp-aes-gcm-03
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Audio/Video Transport Core Maintenance <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Nov 2012 17:31:34 -0000

I have read the draft.

It would be useful to have test vectors for the various algorithms, for implementers to validate their implementations.

The draft needs to specify how header extension encryption (as specified in draft-ietf-avtcore-srtp-encrypted-header-ext) is to be done when using the AES-GCM and AES-CCM algorithms.

I believe the consensus was that it should be done using the equivalent CTR-mode encryption transform, so I'd suggest adding something like the following text to this draft:

[Section Number]. Header Extension Encryption.

When RTP Header Extension Encryption [I-D.ietf-avtcore-srtp-encrypted-header-ext] is in use, a separate keystream is generated to encrypt selected RTP header extension elements.  For the AEAD_AES_128_GCM and the AEAD_AES_128_CCM algorithms, this keystream MUST be generated in the manner defined in [I-D.ietf-avtcore-srtp-encrypted-header-ext] for the AES_128_CM transform.  For the AEAD_AES_256_GCM and the AEAD_AES_256_CCM algorithms, the keystream MUST be generated in the manner defined for the AES_256_CM transform.

-----Original Message-----
From: Magnus Westerlund [mailto:magnus.westerlund@ericsson.com] 
Sent: Tuesday, November 27, 2012 9:21 AM
To: IETF AVTCore WG
Subject: [AVTCORE] Working group last call on draft-ietf-avtcore-srtp-aes-gcm-03

WG,

This announces the WG last call on AES-GCM and AES-CCM Authenticated Encryption in Secure RTP (SRTP) https://datatracker.ietf.org/doc/draft-ietf-avtcore-srtp-aes-gcm/

Please provide any comments no later than the 12th of December. Also comments of the nature of "I have read it and have no comments and think it should be published" are highly valuable.

Cheers

Magnus Westerlund

----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB                | Phone  +46 10 7148287
Färögatan 6                | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------

_______________________________________________
Audio/Video Transport Core Maintenance
avt@ietf.org
https://www.ietf.org/mailman/listinfo/avt