Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?

Christer Holmberg <christer.holmberg@ericsson.com> Thu, 08 June 2017 18:23 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6334412EB01; Thu, 8 Jun 2017 11:23:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level:
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8HDoDSlkf6mP; Thu, 8 Jun 2017 11:23:20 -0700 (PDT)
Received: from sesbmg22.ericsson.net (sesbmg22.ericsson.net [193.180.251.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 54E011250B8; Thu, 8 Jun 2017 11:23:20 -0700 (PDT)
X-AuditID: c1b4fb30-4a9ff70000003fda-98-5939961450bc
Received: from ESESSHC001.ericsson.se (Unknown_Domain [153.88.183.21]) by sesbmg22.ericsson.net (Symantec Mail Security) with SMTP id 3B.9A.16346.41699395; Thu, 8 Jun 2017 20:23:18 +0200 (CEST)
Received: from ESESSMB109.ericsson.se ([169.254.9.30]) by ESESSHC001.ericsson.se ([153.88.183.21]) with mapi id 14.03.0339.000; Thu, 8 Jun 2017 20:23:20 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Cullen Jennings <fluffy@iii.ca>, Flemming Andreasen <fandreas@cisco.com>
CC: Roman Shpount <roman@telurix.com>, Ben Campbell <ben@nostrum.com>, Eric Rescorla <ekr@rtfm.com>, Martin Thomson <martin.thomson@gmail.com>, "mmusic-chairs@ietf.org" <mmusic-chairs@ietf.org>, mmusic <mmusic@ietf.org>
Thread-Topic: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
Thread-Index: AQHS3gR6cOUoIT8u10KHxHCOXLs6qqIWXGKAgAN2xgCAAQSegIAAdFXA
Date: Thu, 08 Jun 2017 18:23:19 +0000
Message-ID: <7594FB04B1934943A5C02806D1A2204B4CBE25D6@ESESSMB109.ericsson.se>
References: <D551D683.1D429%christer.holmberg@ericsson.com> <22C94242-218F-4724-AE92-E0B1E8DC2C82@nostrum.com> <21E8BA9D-E442-4DBC-8A7D-CEDFD5F54F8B@iii.ca> <CAD5OKxujAuzJt4QD6JXKHkVd4JB_nO5Th6KXjavMBww=W4644Q@mail.gmail.com> <6125EAB1-A827-4E0F-B756-78F85BB411CD@iii.ca> <CAD5OKxutcpUzh1yLA2kukmYmiHQg3+6fuXbaD0w73gzsAHEXzg@mail.gmail.com> <e80f0fbe-221e-aa9b-33bd-24d2ff50fe84@cisco.com> <6D9B0AD9-F9C9-4DF6-A2AB-D160094E5FE3@iii.ca>
In-Reply-To: <6D9B0AD9-F9C9-4DF6-A2AB-D160094E5FE3@iii.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [153.88.183.148]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrEIsWRmVeSWpSXmKPExsUyM2K7qK7YNMtIg4YnGhbzO0+zW6x4fY7d 4v0FXYsP638wWlw784/R4vzO9UwWU5c/ZrGYcWEqswOHx5TfG1k9ds66y+6xZMlPJo/L5z8y esza+YTFY/LjNmaPW1MKAtijuGxSUnMyy1KL9O0SuDJe37nHXPBKoOL/y7WMDYzLeLsYOTkk BEwkZv9sYu5i5OIQEjjCKDFl4h0WCGcRo8SLnq+sXYwcHGwCFhLd/7RBGkQEfCRWPzgA1sAs 8JBRov/lc0aQhLBAlcSd1f9YIYqqJTYfv8gG0isi4CbR+sITJMwioCIx/2ozC4jNK+Ar0bRi JxvEroPMEpv+XwSbwylgJfHh/0p2EJtRQEzi+6k1TCA2s4C4xK0n85kgrhaQWLLnPDOELSrx 8jHEXgkBJYnGJU9YIep1JBbs/sQGYWtLLFv4mhlisaDEyZlPWCYwis5CMnYWkpZZSFpmIWlZ wMiyilG0OLU4KTfdyEgvtSgzubg4P08vL7VkEyMwJg9u+W2wg/Hlc8dDjAIcjEo8vB6ilpFC rIllxZW5hxglOJiVRHiPGgCFeFMSK6tSi/Lji0pzUosPMUpzsCiJ8zruuxAhJJCeWJKanZpa kFoEk2Xi4JRqYHTy/qLXvtNd5r1t0qXsCrU1b4UeZTuEZDCr6bO7Ptj6tzFxr1VrSzrb3C8f Nl5sXLbFN/zZXoZ59mwT5tVxflFlt8nJ2Dljb9uqBnHRQ6Jbev6UXvrBpPne6XhOwcGtq423 XtJbc9dnhn517A6ja4UnQ/4Ua5/5LOI5y6rQwjB759xVX0N5VyqxFGckGmoxFxUnAgCSuLDe xQIAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/KAN2AVtC3iBk0WdnUtWijRi5p0k>
Subject: Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Jun 2017 18:23:22 -0000

Hi,

...

>If we agree on the above, I think we could get text that covers that.

We don't "get" text - someone has to produce it :)

Regards,

Christer




> On Jun 7, 2017, at 3:52 PM, Flemming Andreasen <fandreas@cisco.com> wrote:
> 
> Can we get some specific text proposals from the people that seem to care about what we end up with here ? 
> 
> Thanks 
> 
> -- Flemming (as MMUSIC co-chair)
> 
> 
> On 6/5/17 12:58 PM, Roman Shpount wrote:
>> On Mon, Jun 5, 2017 at 10:03 AM, Cullen Jennings <fluffy@iii.ca> wrote:
>> 
>> > On May 31, 2017, at 4:51 PM, Roman Shpount <roman@telurix.com> wrote:
>> >
>> > 1. Starting DTLS handshake until the corresponded answer is received is NOT RECOMMENDED since it can result in unauthenticated media. If unauthenticated media is played to the end user, in cases such as early media in SIP calls, this should be indicated to the end user.
>> 
>> No. Doing the handshake as quickly as possible is recommend - it's what you do with the media before you know who you are talking to that is the issue you are concerned with. And knowing who you are talking often involves much more than checking the fingerprint. So I don't agree this is not recommended.
>> 
>> There are also implementation issues with getting media and not playing it. End point will still need to either buffer or somehow process the received packets so that playback can be started when the answer is received. If handshake is delayed until answer is received, none of this is an issue, so implementation is simpler.
>> 
>> More importantly, I do not think new systems should be built without ICE. I understand there are legacy implementations which use symmetric UDP for media. In such cases it is allowed to complete handshake. Such solutions are legacy and building new systems like this are not recommended. It is recommended that new systems should implement full ICE, consent to send, and do not complete DTLS handshake before an answer SDP is received.
>> 
>> Regards,
>> _____________
>> Roman Shpount
>>  
>