Re: [MMUSIC] actpass redux

Eric Rescorla <ekr@rtfm.com> Mon, 12 June 2017 09:58 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E585127201 for <mmusic@ietfa.amsl.com>; Mon, 12 Jun 2017 02:58:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CNrif3zSQacs for <mmusic@ietfa.amsl.com>; Mon, 12 Jun 2017 02:58:38 -0700 (PDT)
Received: from mail-yw0-x236.google.com (mail-yw0-x236.google.com [IPv6:2607:f8b0:4002:c05::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6535C1294EE for <mmusic@ietf.org>; Mon, 12 Jun 2017 02:58:38 -0700 (PDT)
Received: by mail-yw0-x236.google.com with SMTP id v7so17367272ywc.2 for <mmusic@ietf.org>; Mon, 12 Jun 2017 02:58:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=8brsJJQmvYoHCp8YhWBHpJBXS/lRsv+EKzHLPe1YzMo=; b=VmXbzSqawQS3uruX3eftrw78syetg6t8OQJ31983UEOqapFWfJtzs5O7cudeVI6zJE g782gVHOyKinXJLF5XLSf9EVMLH+dVDF7udbSf8JeEvQMoZwQ1ede+zdGiBK4NqJdPcP GrldNzqcROwmUQqYZ5d7/k5Imh3w1LVa0yRv/PpmNp/5uiTalk1AR6cnJXoVQN1Nja40 Z29PFlLihwzxUrX7tCbZSbmHN+7LWbiIBlPiMnoB8QkPVjkLYIjx+fekknPZJpKDMXH2 Ulca72OpS0Hv9sfNRSoopUsFQvAWpY8ROUw/sVOygTUrmD8qKuvtaNI+BpQqc6A96nk4 xidA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=8brsJJQmvYoHCp8YhWBHpJBXS/lRsv+EKzHLPe1YzMo=; b=s8OEQv9nLjRJc9nulKBhmjL8/mgjeYdNpXijYz+XCGIWsb9rV6Hmj7dk2AuHmC10yh 7nNFijPp7NnrrLFmphRZMGVz4BK8kIXR82HkGHMq19Bwznwe9WyDunwbEizrbB9FmXyI xGrJ83Ly9Rtqr1S+2jlrZlEQ1yO1V+j4CeSPWN8r3eKqRAx3dCmqLrhg/m0r5aQtf74+ Hr6IlqzALH3FDnOBg9I7pr96S6uOwCnJxTqDNSIDIPBUHBucbdyKGPW/xCVhsFUREgap u5kARRj1wYDTY0jqX+zRY7HIKnHP1T7x6WlDry7XTyQn7y14LWs1ew17qBRhRhdXPRBd Y1yQ==
X-Gm-Message-State: AODbwcDoOQxeoWGQp9a8JglO93shXrf2/aLnIpGtdUOOkMfgIDUfPKvm guePySb1+hanNIyxx9S9v4qAXtVCxkx9
X-Received: by 10.129.109.4 with SMTP id i4mr25078138ywc.3.1497261517648; Mon, 12 Jun 2017 02:58:37 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.13.215.144 with HTTP; Mon, 12 Jun 2017 02:57:56 -0700 (PDT)
In-Reply-To: <D5641A33.1E1FE%christer.holmberg@ericsson.com>
References: <CABcZeBMd2BZgyeFnqafTVyGga4FMoK0xJkPCv0y_wvmBWsg+xg@mail.gmail.com> <CAD5OKxvwgvm3Q4HsCYsewZjRS9ty_g34n9+x87vfLW4Omcm8mw@mail.gmail.com> <CAD5OKxuNvnBgpv7BO3fv27ASu5AMugh4-LNpq1r8ga5OtqD_nw@mail.gmail.com> <CABcZeBNELXgQjuYfsrJG9NCsQz8Tox8d3ktvoo3nqPgjESEXZw@mail.gmail.com> <6355EA0B-2C28-4D47-9600-F64F898BFC86@iii.ca> <CAD5OKxttSJ+0Gr2r1=duXe2RVnMeMoTFQ9kG_qUbVUZgiiB3kA@mail.gmail.com> <14ED932A-FCC7-4C4A-93BB-627A4E55F552@iii.ca> <c6a3c314-7089-19f6-5d67-f7ea77f97894@comcast.net> <CAD5OKxsd0saF1bLAORon25wk+MwyoCC6AkP-wSfEmYP7MNzV3Q@mail.gmail.com> <CABcZeBOKvGEWJUDvxfBcXn2DTmFyb8hvp8mD=NMj1-bum3tLFw@mail.gmail.com> <D5641A33.1E1FE%christer.holmberg@ericsson.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Mon, 12 Jun 2017 10:57:56 +0100
Message-ID: <CABcZeBPK5T-=S14+U7LHhwPH0TQ9CHv32qVzZd4XUevNKcuXnQ@mail.gmail.com>
To: Christer Holmberg <christer.holmberg@ericsson.com>
Cc: Roman Shpount <roman@telurix.com>, Paul Kyzivat <paul.kyzivat@comcast.net>, "mmusic@ietf.org" <mmusic@ietf.org>
Content-Type: multipart/alternative; boundary="001a114dd184e5bbe20551c05cf1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/O1AHMYufwtQHFZrL9Hw_3EiX0z8>
Subject: Re: [MMUSIC] actpass redux
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Jun 2017 09:58:40 -0000

On Mon, Jun 12, 2017 at 8:33 AM, Christer Holmberg <
christer.holmberg@ericsson.com> wrote:

> Hi,
>
> First, one of the reasons we update specs is because there are usages etc,
> that people weren’t aware of when the original spec was published, that we
> think we need to cover. So, rather than just saying that we don’t care
> about non-comformant endpoints, we should ask WHY they are non-comformant.
> Is there a specific use-case behind? If so, do we need to cover that
> use-case?
>

Yes, and one of the things we have to keep in mind is not breaking
conformant endpoints.


Second, keep in mind that while RFC 5763 is for DTLS-SRTP, draft-dtls-sdp
> is GENERIC - one of the main reasons we do the spec in the first place is
> to have the DTLS-related O/A procedures in one place. And, RFC 7345
> (UDPTL-DTLS) DOES allow non-actpass values in the offer:
>
> 	"The offerer SHOULD assign the SDP "setup" attribute with a value of
>    	"actpass", unless the offerer insists on being either the sender or
>    	receiver of the DTLS ClientHello message,"
>
> draft-dtls-sdp replaces that text with a reference to draft-dtls-sdp, and
> by mandating actpass we would remove a valid option for UDPTL-DTLS. Sure,
> we can do that, but it cannot be based on a claim that existing endpoints
> are non-comformant.
>
> And, I do NOT think we want to allow non-actpass for some usages (e.g.,
> UDPTL-DTLS), and forbid it for other usages (e.g., DTLS-SRTP), because that
> would go against the purpose of having generic DTLS O/A procedures.
>

Well, given that we apparently have incompatible existing RFCs, I'm not
sure I see any
alternative.

-Ekr


> Regards,
>
> Christer
>
>
> From: mmusic <mmusic-bounces@ietf.org> on behalf of Eric Rescorla <
> ekr@rtfm.com>
> Date: Saturday 10 June 2017 at 12:34
> To: Roman Shpount <roman@telurix.com>
> Cc: Paul Kyzivat <paul.kyzivat@comcast.net>, "mmusic@ietf.org" <
> mmusic@ietf.org>
> Subject: Re: [MMUSIC] actpass redux
>
>
>
> On Fri, Jun 9, 2017 at 7:23 PM, Roman Shpount <roman@telurix.com> wrote:
>
>> On Fri, Jun 9, 2017 at 2:00 PM, Paul Kyzivat <paul.kyzivat@comcast.net>
>> wrote:
>>
>>> On 6/9/17 9:17 AM, Cullen Jennings wrote:
>>>
>>>>
>>>> On Jun 8, 2017, at 6:49 PM, Roman Shpount <roman@telurix.com> wrote:
>>>>>
>>>>>   Because of this, I think for the best interop, offerer MUST specify
>>>>> actpass for both initial and subsequent offers but answerer MUST be able to
>>>>> handle active and passive setup roles as well.
>>>>>
>>>>
>>>> that works for me
>>>>
>>>
>>> I don't understand what this accomplishes. If you must be able to accept
>>> anything in a received offer, then what is gained by restricting what can
>>> be used in an offer?
>>>
>>
>> This is all because of legacy interop. There are legacy end points that
>> send non-actpass, so end point MUST be able to accept active and passive to
>> interop with such legacy devices.
>>
>
> Those legacy endpoints are clearly noncomformant, so I'm not sure I care
> about breaking them,
>
>
>
>> There are also legacy end points that only expect actass so end point
>> MUST only send actpass to interop with such devices.
>>
>
> These legacy endpoints are conformant, which is why it's important to
> accommodate them
>
> -Ekr
>
>
>> _____________
>> Roman Shpount
>>
>>
>> _______________________________________________
>> mmusic mailing list
>> mmusic@ietf.org
>> https://www.ietf.org/mailman/listinfo/mmusic
>>
>>
>