Re: [clue] Eric Rescorla's No Objection on draft-ietf-clue-signaling-14: (with COMMENT)

Eric Rescorla <ekr@rtfm.com> Sun, 25 November 2018 19:30 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: clue@ietfa.amsl.com
Delivered-To: clue@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 786A7130DCA for <clue@ietfa.amsl.com>; Sun, 25 Nov 2018 11:30:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.358
X-Spam-Level:
X-Spam-Status: No, score=-3.358 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-1.459, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dlXbYo_g-5q6 for <clue@ietfa.amsl.com>; Sun, 25 Nov 2018 11:30:14 -0800 (PST)
Received: from mail-lj1-x22f.google.com (mail-lj1-x22f.google.com [IPv6:2a00:1450:4864:20::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CF381124C04 for <clue@ietf.org>; Sun, 25 Nov 2018 11:30:13 -0800 (PST)
Received: by mail-lj1-x22f.google.com with SMTP id c19-v6so14588827lja.5 for <clue@ietf.org>; Sun, 25 Nov 2018 11:30:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=rA+Kw7uR5fgNvVl9tEJkb2CXwtFEZ4JunwpNWISQ6BA=; b=nISc/bJ5zGU1IHwNsyaZQsAk2Hr6teIePobT+tjXmnNNo7XtHQQITQEcfFtnUystOO N+gWQMLn+FFS3gFv4bSBqwyuj8pNbJ26MMgCsSR1KL20UpEZ3RUMnoQJFBi2jpFlmyy1 ML7xkDpQLtZYa/1pVARuSgEEOT564WoMV452V/XvzCUXIBI4wsp7Z75gyR9ZY83mRwOz 7tZ7pmr0AZtvPQwdk3VDw5EmBHdQTqySZFEuhzKc3BOpJRbOZFVLCkODSfV9S7vAqw22 jzlSp5OhT+xJxhOg0olOhFk61OtlTQ3gJttRNTiYIQUrb7vJ5hiNjQr9+1oHCySL7KGW LSLg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=rA+Kw7uR5fgNvVl9tEJkb2CXwtFEZ4JunwpNWISQ6BA=; b=W0ufgY9QkDcuHyNdMvW4+fV7wWWeZYdw2nvwB/SeiNoap17mZzzVBv/H2tkrpSj5Lt jEfSSECYsspLH0VtIxw/38DLrPvWtCVlgcepdmNke2ICDfNQBx9HQ8vzX+mdKY51ajP+ ZDRPHnrqp4uECFp+oMvtzxYEkvVFDzLXMzMHMIW9KGxsgyI9AzQcYf/U9cHhIr58P4y/ 34zbFxCI1Rc/LUusz0ziDrj+XlWLdlezfjnH5fvBM8Dj/PAB7vS7I7C/KzUd3BrKpq3m Cnr6z7eJtbYmngtvKXZSQDqytIu+2CC1M9u1PQQz5g1u38oQstMhBul95KEb67UwX1TK XeCg==
X-Gm-Message-State: AA+aEWZXg1ZrL6C3dosE9aBmfB1345csZYjRfhll8RVQPjYvbDA3/xOZ UC4eMYcVR3Ovr1ckmbCz+1j1yYi8nc9JUxwyL8jzZQ==
X-Google-Smtp-Source: AFSGD/XEKppLgjkp881mMb60uRbhi/JxO7Eas/pTzr/5kv5LvUznPNDqj7mfalQmpf0i/wmIfSXLUDDQbZ9MdkCn5Tc=
X-Received: by 2002:a2e:9a84:: with SMTP id p4-v6mr14812367lji.73.1543174211931; Sun, 25 Nov 2018 11:30:11 -0800 (PST)
MIME-Version: 1.0
References: <154268892146.26648.17870778354406192041.idtracker@ietfa.amsl.com> <6E58094ECC8D8344914996DAD28F1CCD18C762DF@DGGEMM506-MBX.china.huawei.com> <CABcZeBMcQxZuRUFx=tz==C5eCc8zNBrxkKaZfBa+gYnyaV3FOQ@mail.gmail.com> <6E58094ECC8D8344914996DAD28F1CCD18C7B5DE@DGGEMM506-MBS.china.huawei.com> <CABcZeBOPPojS2zsR6uZCagcs7yBBmtMW9rcyPw_gEK44u7GH1w@mail.gmail.com> <b9922f72-932c-a509-95c2-c86765d5ce6d@alum.mit.edu>
In-Reply-To: <b9922f72-932c-a509-95c2-c86765d5ce6d@alum.mit.edu>
From: Eric Rescorla <ekr@rtfm.com>
Date: Sun, 25 Nov 2018 11:29:34 -0800
Message-ID: <CABcZeBNb4nG7U9KdMLCT8f4oOYXqWydM_1JQPbfceSu31+Bg1A@mail.gmail.com>
To: Paul Kyzivat <pkyzivat@alum.mit.edu>
Cc: Roni Even <roni.even@huawei.com>, IESG <iesg@ietf.org>, Daniel Burnett <danielcburnett@gmail.com>, clue@ietf.org, roni.even@mail01.huawei.com, clue-chairs@ietf.org, draft-ietf-clue-signaling@ietf.org
Content-Type: multipart/alternative; boundary="000000000000baa370057b823e3d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/clue/fGBdlxV9SKT_SklR9XjJAfzOiXs>
Subject: Re: [clue] Eric Rescorla's No Objection on draft-ietf-clue-signaling-14: (with COMMENT)
X-BeenThere: clue@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: CLUE - ControLling mUltiple streams for TElepresence <clue.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/clue>, <mailto:clue-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/clue/>
List-Post: <mailto:clue@ietf.org>
List-Help: <mailto:clue-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/clue>, <mailto:clue-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 25 Nov 2018 19:30:15 -0000

On Sun, Nov 25, 2018 at 9:35 AM Paul Kyzivat <pkyzivat@alum.mit.edu> wrote:

> On 11/25/18 8:14 AM, Eric Rescorla wrote:
> >
> >
> > On Sat, Nov 24, 2018 at 9:41 PM Roni Even (A) <roni.even@huawei.com
> > <mailto:roni.even@huawei.com>> wrote:
> >
> >     Hi,____
> >
> >     The point that is made that in general CLUE is similar to no CLUE
> >     RTP media calls. The difference is that since the EP may open more
> >     than one RTP video channel there is a greater risk of sending more
> >     media to the victim.
> >
> >
> > Yes, but in order to have a useful countermeasure, that needs to be
> > mandatory, and yours is not.
>
> But one of the goals of clue is to be backward compatible with regular
> sip calls. If we impose constraints on the media over and above those
> required for regular sip calls then we lose that.
>

ISTM that that's already not true for these media flows, because 4.4.1
requires them to
be inactive and you need to use an SCTP/DTLS control channel to negotiate
them.
What I'm saying is that those other flows should also have a consent check

-Ekr


>         Thanks,
>         Paul
>