Re: [MMUSIC] Draft new version: draft-holmberg-mmusic-sdp-dtls-01

Christer Holmberg <christer.holmberg@ericsson.com> Mon, 22 June 2015 11:27 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66ED21B2F89 for <mmusic@ietfa.amsl.com>; Mon, 22 Jun 2015 04:27:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kp2710WdjZEf for <mmusic@ietfa.amsl.com>; Mon, 22 Jun 2015 04:26:58 -0700 (PDT)
Received: from sessmg22.ericsson.net (sessmg22.ericsson.net [193.180.251.58]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 408451B2F84 for <mmusic@ietf.org>; Mon, 22 Jun 2015 04:26:58 -0700 (PDT)
X-AuditID: c1b4fb3a-f79ec6d000006dc0-26-5587f1003aa5
Received: from ESESSHC009.ericsson.se (Unknown_Domain [153.88.253.125]) by sessmg22.ericsson.net (Symantec Mail Security) with SMTP id 32.F0.28096.001F7855; Mon, 22 Jun 2015 13:26:56 +0200 (CEST)
Received: from ESESSMB209.ericsson.se ([169.254.9.27]) by ESESSHC009.ericsson.se ([153.88.183.45]) with mapi id 14.03.0210.002; Mon, 22 Jun 2015 13:26:55 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Salvatore Loreto <salvatore.loreto@ericsson.com>, Martin Thomson <martin.thomson@gmail.com>
Thread-Topic: [MMUSIC] Draft new version: draft-holmberg-mmusic-sdp-dtls-01
Thread-Index: AdCrWa7CoSEAxl9nTzqDK97DYyB2FgAFrAaAAAzv3QAARwSIAAAHicxa
Date: Mon, 22 Jun 2015 11:26:55 +0000
Message-ID: <7594FB04B1934943A5C02806D1A2204B1D8F60AA@ESESSMB209.ericsson.se>
References: <7594FB04B1934943A5C02806D1A2204B1D8F4457@ESESSMB209.ericsson.se> <5585A71F.4080808@alum.mit.edu> <7594FB04B1934943A5C02806D1A2204B1D8F4863@ESESSMB209.ericsson.se>, <10715029-3F5B-4D4D-82B8-B842B4C1629A@ericsson.com>
In-Reply-To: <10715029-3F5B-4D4D-82B8-B842B4C1629A@ericsson.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Content-Type: multipart/alternative; boundary="_000_7594FB04B1934943A5C02806D1A2204B1D8F60AAESESSMB209erics_"
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmpmkeLIzCtJLcpLzFFi42KZGfG3VpfhY3uowZ1XChbXzvxjtJi6/DGL xYoNB1gdmD3+vv/A5LFz1l12jyVLfjIFMEdx2aSk5mSWpRbp2yVwZayedpC94LdRxek9V9ga GHu0uxg5OSQETCQuHXvPCmGLSVy4t56ti5GLQ0jgKKPEpZY2RghnMaPEyd7pQA4HB5uAhUT3 P7BmEYFEiU0H5zOC2MwCvhIvF3xhBrGFBbwkXh1tYwEpFxHwlni92gai3E1iz/cnTCA2i4Cq xISLP8HKeYFar12dDLX3OaPEnav7WEASnAIOEp+nvQObzwh03PdTa5ggdolLNH1ZCXW0gMSS PeeZIWxRiZeP/7FC1ORLPNhzjhFigaDEyZlPWCYwisxC0j4LSdksJGUQcQOJL+9vQ9naEssW vmaGsPUlut+fZkIWX8DIvopRtDi1uDg33chIL7UoM7m4OD9PLy+1ZBMjMNYObvlttYPx4HPH Q4wCHIxKPLwKOe2hQqyJZcWVuYcYpTlYlMR5Z2zOCxUSSE8sSc1OTS1ILYovKs1JLT7EyMTB KdXAuPjQyqCKsuvnBJ0Sstd+MRBziV1VWJ4nEVW/lllozj5VhU6+V/kxexiWuP5oqfn2sDIh +HBPmc8mm1ffxGJDQu4c+iq8+G3D9c2dmW+uTzrw7aXrjZpUbWcR2xrPB8V1RpfjGvdtddy5 N6Q46IPjnv27syVM2+YtORTZuyiD4znHLOmItbLqSizFGYmGWsxFxYkAEHwCAZYCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/mmusic/HPdU566y4IFjUIWcCyVb3J4QP3Q>
Cc: "mmusic@ietf.org" <mmusic@ietf.org>, Paul Kyzivat <pkyzivat@alum.mit.edu>
Subject: Re: [MMUSIC] Draft new version: draft-holmberg-mmusic-sdp-dtls-01
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Jun 2015 11:27:00 -0000

Hi Sal,

Unless you change the transport parameters, you may receive DTLS packets associated with the old and new DTLS association on the same address:port.

Regards,

Christer

Sent from my Windows Phone
________________________________
From: Salvatore Loreto<mailto:salvatore.loreto@ericsson.com>
Sent: ‎22/‎06/‎2015 12:51
To: Christer Holmberg<mailto:christer.holmberg@ericsson.com>; Martin Thomson<mailto:martin.thomson@gmail.com>
Cc: Paul Kyzivat<mailto:pkyzivat@alum.mit.edu>; mmusic@ietf.org<mailto:mmusic@ietf.org>
Subject: Re: [MMUSIC] Draft new version: draft-holmberg-mmusic-sdp-dtls-01


> On 21 Jun 2015, at 01:05, Christer Holmberg <christer.holmberg@ericsson.com> wrote:
>
> Hi Paul,
>
> Thanks for your comments. See inline.
>
>
>> * Section 2.1:
>>
>>   When a new DTLS association is established, an endpoint MUST use a
>>   new set of transport parameters (IP address and port combination).
>>
>> The above seems slightly ambiguous: does "an endpoint" mean "each endpoint" or "one (of the two) endpoints"?
>>
>> IIUC we have established that the important point is that the 5-tuple must change. So at least one side must change the address or port. But if one > side is known to do so, then the other side need not do so. So I suggest changing the above to:
>>
>>   When a new DTLS association is established, one of the endpoints
>>   MUST use a new set of transport parameters (IP address and port
>>   combination).
>
> The idea is that the endpoint(s) which does something the requires a new set of transport parameters needs to use a new set.
>
> So, if e.g. endpoint A wants to change the fingerprint, which requires a new DTLS association, endpoint A needs to use a new set of transport parameters.

I agree that
If you change the certificate you intend to use, then you need a new DTLS association

however I am not sure that this (i.e. the change of the certificate) also implies the endpoint has to use necessary a new set of transport parameters.

Can you someone clarify this to me?

thanks
/Sal