Re: [Geopriv] Please note: Re: I-D Action: draft-ietf-geopriv-deref-protocol-06.txt

Robert Sparks <rjsparks@nostrum.com> Fri, 13 July 2012 14:30 UTC

Return-Path: <rjsparks@nostrum.com>
X-Original-To: geopriv@ietfa.amsl.com
Delivered-To: geopriv@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 155C921F86A7 for <geopriv@ietfa.amsl.com>; Fri, 13 Jul 2012 07:30:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level:
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, SPF_PASS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XB-V72JJSyGR for <geopriv@ietfa.amsl.com>; Fri, 13 Jul 2012 07:30:00 -0700 (PDT)
Received: from nostrum.com (nostrum-pt.tunnel.tserv2.fmt.ipv6.he.net [IPv6:2001:470:1f03:267::2]) by ietfa.amsl.com (Postfix) with ESMTP id 5053521F877B for <geopriv@ietf.org>; Fri, 13 Jul 2012 07:29:59 -0700 (PDT)
Received: from unexplicable.local ([4.30.77.1]) (authenticated bits=0) by nostrum.com (8.14.3/8.14.3) with ESMTP id q6DEUUwg085587 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=OK); Fri, 13 Jul 2012 09:30:30 -0500 (CDT) (envelope-from rjsparks@nostrum.com)
Message-ID: <50003106.2080800@nostrum.com>
Date: Fri, 13 Jul 2012 09:30:30 -0500
From: Robert Sparks <rjsparks@nostrum.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:13.0) Gecko/20120614 Thunderbird/13.0.1
MIME-Version: 1.0
To: "Richard L. Barnes" <rbarnes@bbn.com>
References: <20120711231357.12731.12817.idtracker@ietfa.amsl.com> <4FFF145D.9050409@nostrum.com> <6277DD8F-3932-45B8-A68A-04820E0EAA55@bbn.com>
In-Reply-To: <6277DD8F-3932-45B8-A68A-04820E0EAA55@bbn.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Received-SPF: pass (nostrum.com: 4.30.77.1 is authenticated by a trusted mechanism)
Cc: geopriv@ietf.org, draft-ietf-geopriv-deref-protocol@tools.ietf.org, sec-ads@tools.ietf.org
Subject: Re: [Geopriv] Please note: Re: I-D Action: draft-ietf-geopriv-deref-protocol-06.txt
X-BeenThere: geopriv@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Geographic Location/Privacy <geopriv.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/geopriv>, <mailto:geopriv-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/geopriv>
List-Post: <mailto:geopriv@ietf.org>
List-Help: <mailto:geopriv-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/geopriv>, <mailto:geopriv-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Jul 2012 14:30:03 -0000

Hi Richard.

Where you say "be configure to" and "respond to", do you mean "be 
configured to only" and "respond only to"?

RjS

On 7/12/12 2:35 PM, Richard L. Barnes wrote:
> <hat type="individual"/>
>
> I would prefer that this text make a little clearer which entities in the protocol are required to do something and when.
>
> OLD:
> "
> TLS SHOULD be used.
> "
>
> NEW:
> "
> The scheme of a location URI determines whether or not TLS is used on a given dereference transaction.  Location Servers MUST be configured to issue HTTPS URIs and respond to HTTPS dereference request, unless confidentiality and integrity protection are provided by some other mechanism.  For example, the server might only accept requests from clients within a trusted network, or via an IPsec-protected channel.  Dereference clients MUST support dereference of HTTPS URIs and SHOULD support dereference of HTTP URIs.
> "
>
>
>
>
>
> On Jul 12, 2012, at 2:15 PM, Robert Sparks wrote:
>
>> This revision addressed all the points from IESG review.
>>
>> Notably, it contained a clarification to when TLS is required:
>>
>> OLD:
>>    TLS SHOULD be used.
>>
>> NEW:
>>     TLS MUST be used unless confidentiality and integrity are provided by
>>     some other mechanism, such as IPsec or a fully trusted network.
>>     Without a reliable assertion that a mechanism is in place, such as
>>     through configuration or user override, then TLS MUST be used.
>>
>> If you have a concern with this change, please let me know ASAP.
>> If I haven't heard anything I'll approve the document towards the end of next week.
>>
>> RjS
>>   
>> On 7/11/12 6:13 PM, internet-drafts@ietf.org wrote:
>>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>>>   This draft is a work item of the Geographic Location/Privacy Working Group of the IETF.
>>>
>>> 	Title           : A Location Dereferencing Protocol Using HELD
>>> 	Author(s)       : James Winterbottom
>>>                            Hannes Tschofenig
>>>                            Henning Schulzrinne
>>>                            Martin Thomson
>>> 	Filename        : draft-ietf-geopriv-deref-protocol-06.txt
>>> 	Pages           : 23
>>> 	Date            : 2012-07-11
>>>
>>> Abstract:
>>>     This document describes how to use the Hypertext Transfer Protocol
>>>     (HTTP) over Transport Layer Security (TLS) as a dereferencing
>>>     protocol to resolve a reference to a Presence Information Data Format
>>>     Location Object (PIDF-LO).  The document assumes that a Location
>>>     Recipient possesses a URI that can be used in conjunction with the
>>>     HTTP-Enabled Location Delivery (HELD) protocol to request the
>>>     location of the Target.
>>>
>>>
>>> The IETF datatracker status page for this draft is:
>>>
>>> https://datatracker.ietf.org/doc/draft-ietf-geopriv-deref-protocol
>>>
>>>
>>> There's also a htmlized version available at:
>>>
>>> http://tools.ietf.org/html/draft-ietf-geopriv-deref-protocol-06
>>>
>>>
>>> A diff from previous version is available at:
>>>
>>> http://tools.ietf.org/rfcdiff?url2=draft-ietf-geopriv-deref-protocol-06
>>>
>>>
>>>
>>> Internet-Drafts are also available by anonymous FTP at:
>>>
>>> ftp://ftp.ietf.org/internet-drafts/
>>>
>>>
>>> _______________________________________________
>>> Geopriv mailing list
>>>
>>> Geopriv@ietf.org
>>> https://www.ietf.org/mailman/listinfo/geopriv
>>
>> _______________________________________________
>> Geopriv mailing list
>> Geopriv@ietf.org
>> https://www.ietf.org/mailman/listinfo/geopriv