Re: [Gen-art] Gen-ART review of draft-ietf-tram-stun-origin-05

Alan Johnston <alan.b.johnston@gmail.com> Tue, 21 April 2015 11:21 UTC

Return-Path: <alan.b.johnston@gmail.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1DD481A9244; Tue, 21 Apr 2015 04:21:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BB7U19qXxHOl; Tue, 21 Apr 2015 04:21:22 -0700 (PDT)
Received: from mail-vn0-x22e.google.com (mail-vn0-x22e.google.com [IPv6:2607:f8b0:400c:c0f::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6BC0D1A9240; Tue, 21 Apr 2015 04:21:22 -0700 (PDT)
Received: by vnbg62 with SMTP id g62so32590846vnb.7; Tue, 21 Apr 2015 04:21:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=HkR0NddXgbOCTRMfKe2msMXO5MhDBEcxxdGdGLZn0vA=; b=BxD1QVSX0mpe2oWKZHB+V9tA/oIrlay4GTHs5aIRTb+BsRRiYtSLqWuif5Egsis/02 NnDlnb+VTG6cxMQ1hHwNsmIzX5nGBxLBXXwA92lo7NAdzs1x4pTe1kaE/nblkMCGWbVz UauyswdG+yRj7MV7VuuoeFC1ye0lbL3Tj34pNxWCOWHRGEuJpHsjzw6S7J3YWi9dQqy8 CkBb6CNZVXcdBsxcaouMIUhwce0E3Ptiwxqx7rqdLfMe54iq29DrRZclILguaf+IERtS VU01u1L0oBt9HyLYn/vi5PSokICKDwbnXl7Y6/myqDzvLccclQ9KfoPP2Uslsom2OOcE LXCw==
MIME-Version: 1.0
X-Received: by 10.52.24.113 with SMTP id t17mr21470817vdf.89.1429615281622; Tue, 21 Apr 2015 04:21:21 -0700 (PDT)
Received: by 10.52.106.100 with HTTP; Tue, 21 Apr 2015 04:21:21 -0700 (PDT)
In-Reply-To: <EC554156-5C29-440F-ACF8-95008EE481AE@piuha.net>
References: <CE03DB3D7B45C245BCA0D2432779493641B3BE@MX104CL02.corp.emc.com> <EC554156-5C29-440F-ACF8-95008EE481AE@piuha.net>
Date: Tue, 21 Apr 2015 06:21:21 -0500
Message-ID: <CAKhHsXFtr7LoS1HDd5YR5fxDbfUugNZ5r_f-P9XAq4O2qVheFA@mail.gmail.com>
Subject: Re: [Gen-art] Gen-ART review of draft-ietf-tram-stun-origin-05
From: Alan Johnston <alan.b.johnston@gmail.com>
To: Jari Arkko <jari.arkko@piuha.net>
Content-Type: multipart/alternative; boundary="20cf307c9d9e06d3c805143a3f43"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/C-5ULXJyRzo762QT_WOJrsWmXAg>
Cc: "justin@uberti.name" <justin@uberti.name>, "tram@ietf.org" <tram@ietf.org>, "Black, David" <david.black@emc.com>, "yoakum@avaya.com" <yoakum@avaya.com>, "General Area Review Team (gen-art@ietf.org)" <gen-art@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Apr 2015 11:21:25 -0000

Hi Jari,

We unfortunately did not reply to David for his review - our mistake.  See
below for our response.

- Alan -

On Tue, Apr 21, 2015 at 1:55 AM, Jari Arkko <jari.arkko@piuha.net> wrote:

> Thanks for your review, David. I am trying to determine
> how to deal with this draft in the upcoming IESG telechat.
> Has there been any discussion of the issue you raise?
> Do the authors have a response?
>
> Jari
>
> On 21 Mar 2015, at 06:12, Black, David <david.black@emc.com> wrote:
>
> > I am the assigned Gen-ART reviewer for this draft. For background on
> > Gen-ART, please see the FAQ at
> >
> > <http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.
> >
> > Please resolve these comments along with any other Last Call comments
> > you may receive.
> >
> > Document: draft-ietf-tram-stun-origin-05
> > Reviewer: David L. Black
> > Review Date: March 20, 2015
> > IETF LC End Date: March 17, 2015
> >
> > Summary: This draft is on the right track, but has open issues
> >               described in the review.
> >
> > This draft describes the addition of a web origin attribute to STUN and
> > usage of that attribute in several protocol contexts.  The draft is well-
> > written and easy to read.  I found one minor issue which may be
> editorial.
> >
> > Major issues: None.
> >
> > Minor issues:
> >
> > Section 2.7 discusses use of multiple STUN origins with Web RTC and
> > concludes by imposing a "MUST" requirement on use of multiple STUN
> > origins with HTTP in general (use first origin, ignore others).  While
> > Web RTC may be the predominant or only current use of STUN and TURN with
> > HTTP, this "MUST" could foreclose the use of STUN origins with other
> > uses of HTTP.  I'm not sure what those possible future uses might be,
> > but at a minimum this draft ought to more tightly scope its discussion
> > of use of STUN origins with HTTP to limit that usage to Web RTC.  If
> > there's a good way for a STUN or TURN server to detect Web RTC usage,
> > requiring STUN and TURN servers to look for Web RTC as the use of
> > HTTP, and only impose this "MUST" requirement if Web RTC is detected
> > would better align that requirement with the discussion in this draft.
>

David,

Apologies for not responding to you earlier earlier.  Since this text was
written, we have realized that there are no valid use cases for HTTP, SIP,
or XMPP for multiple Origins, and also that the STUN specification says
that even if multiples were sent, only the first will be processed.  So we
are dropping the MUST that you reference here.  We also plan to change the
multiple Origins language in section 2 to say:

"Senders SHOULD NOT include multiple ORIGIN attributes in a request since
per STUN rules, only the first will be processed and the rest ignored."


> >
> > Nits/editorial comments:
> >
> > idnits 2.13.01 turned up a reference problem:
> >
> >  == Unused Reference: 'RFC7350' is defined on line 490, but no explicit
> >     reference was found in the text
> >
> > That RFC should be cited somewhere.  In addition, there are no RFCs cited
> > or referenced for TLS and DTLS - they should be added (I believe that
> > RFC 5246 and RFC 6347 are appropriate, respectively).
>

RFC 7350 is DTLS transport for STUN, so we should reference it in the
Security Considerations when we discuss DTLS.


> >
> > Thanks,
> > --David
> > ----------------------------------------------------
> > David L. Black, Distinguished Engineer
> > EMC Corporation, 176 South St., Hopkinton, MA  01748
> > +1 (508) 293-7953             FAX: +1 (508) 293-7786
> > david.black@emc.com        Mobile: +1 (978) 394-7754
> > ----------------------------------------------------
> >
> >
> > _______________________________________________
> > Gen-art mailing list
> > Gen-art@ietf.org
> > https://www.ietf.org/mailman/listinfo/gen-art
>
>