[AVT] draft-ietf-avt-ports-for-ucast-mcast-rtp-04

"DRAGE, Keith (Keith)" <keith.drage@alcatel-lucent.com> Wed, 01 December 2010 14:49 UTC

Return-Path: <keith.drage@alcatel-lucent.com>
X-Original-To: avt@core3.amsl.com
Delivered-To: avt@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D3AA83A6B40 for <avt@core3.amsl.com>; Wed, 1 Dec 2010 06:49:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.615
X-Spam-Level:
X-Spam-Status: No, score=-103.615 tagged_above=-999 required=5 tests=[AWL=-1.366, BAYES_00=-2.599, HELO_EQ_FR=0.35, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rDubd2w0mz22 for <avt@core3.amsl.com>; Wed, 1 Dec 2010 06:49:06 -0800 (PST)
Received: from smail6.alcatel.fr (smail6.alcatel.fr [64.208.49.42]) by core3.amsl.com (Postfix) with ESMTP id DE94D3A6A1A for <avt@ietf.org>; Wed, 1 Dec 2010 06:49:05 -0800 (PST)
Received: from FRMRSSXCHHUB03.dc-m.alcatel-lucent.com (FRMRSSXCHHUB03.dc-m.alcatel-lucent.com [135.120.45.63]) by smail6.alcatel.fr (8.14.3/8.14.3/ICT) with ESMTP id oB1EoBL4002247 (version=TLSv1/SSLv3 cipher=RC4-MD5 bits=128 verify=NOT) for <avt@ietf.org>; Wed, 1 Dec 2010 15:50:18 +0100
Received: from FRMRSSXCHMBSC3.dc-m.alcatel-lucent.com ([135.120.45.46]) by FRMRSSXCHHUB03.dc-m.alcatel-lucent.com ([135.120.45.63]) with mapi; Wed, 1 Dec 2010 15:50:13 +0100
From: "DRAGE, Keith (Keith)" <keith.drage@alcatel-lucent.com>
To: 'IETF AVT WG' <avt@ietf.org>
Date: Wed, 01 Dec 2010 15:46:38 +0100
Thread-Topic: draft-ietf-avt-ports-for-ucast-mcast-rtp-04
Thread-Index: AcuRZo8n5SLP+sUjTTqvKtzeX69Kig==
Message-ID: <EDC0A1AE77C57744B664A310A0B23AE21E36365D@FRMRSSXCHMBSC3.dc-m.alcatel-lucent.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Scanned-By: MIMEDefang 2.64 on 155.132.188.84
Subject: [AVT] draft-ietf-avt-ports-for-ucast-mcast-rtp-04
X-BeenThere: avt@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Audio/Video Transport Working Group <avt.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/avt>
List-Post: <mailto:avt@ietf.org>
List-Help: <mailto:avt-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/avt>, <mailto:avt-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Dec 2010 14:49:07 -0000

(As WG chair)

At the AVT face to face meeting in Beijing, there was considerable discussion on the security issues regarding token versus cookie.

My only conclusion from that discussion was that the text needs to be improved, and shortening the timer may provide the only real solution to such attacks. 

Has this issue been nailed down and closed in the -04 version of the document, or is more work still required?

In particular I'd like to see responses from EKR, Magnus and Colin, who all indicated more work was required in Beijing.

regards

Keith