Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?

Christer Holmberg <christer.holmberg@ericsson.com> Tue, 23 May 2017 09:52 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF95A128D19 for <mmusic@ietfa.amsl.com>; Tue, 23 May 2017 02:52:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level:
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VxibOtiBzE8a for <mmusic@ietfa.amsl.com>; Tue, 23 May 2017 02:52:11 -0700 (PDT)
Received: from sessmg22.ericsson.net (sessmg22.ericsson.net [193.180.251.58]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 30422127286 for <mmusic@ietf.org>; Tue, 23 May 2017 02:52:11 -0700 (PDT)
X-AuditID: c1b4fb3a-6e3519a000004a6a-b9-59240649777f
Received: from ESESSHC010.ericsson.se (Unknown_Domain [153.88.183.48]) by sessmg22.ericsson.net (Symantec Mail Security) with SMTP id 7C.10.19050.94604295; Tue, 23 May 2017 11:52:09 +0200 (CEST)
Received: from ESESSMB109.ericsson.se ([169.254.9.30]) by ESESSHC010.ericsson.se ([153.88.183.48]) with mapi id 14.03.0339.000; Tue, 23 May 2017 11:52:06 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Cullen Jennings <fluffy@iii.ca>
CC: "mmusic@ietf.org" <mmusic@ietf.org>
Thread-Topic: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
Thread-Index: AQHSzg+3LES5P8e96kuYQ2NFd1Iy/aIBHgAAgACsxIA=
Date: Tue, 23 May 2017 09:52:06 +0000
Message-ID: <D549E236.1D087%christer.holmberg@ericsson.com>
References: <D5407B8A.1C98B%christer.holmberg@ericsson.com> <178E77C7-CB9B-4D5D-A0F9-627153C03FEE@iii.ca>
In-Reply-To: <178E77C7-CB9B-4D5D-A0F9-627153C03FEE@iii.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.7.2.170228
x-originating-ip: [153.88.183.19]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <99F53828372708489B7AFB5FBC6FD69D@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprLIsWRmVeSWpSXmKPExsUyM2K7ga4nm0qkwckrUhYf1v9gtJi6/DGL A5PHkiU/mTwun//IGMAUxWWTkpqTWZZapG+XwJUxfbNiwSyOikdvT7M3MB5j62Lk5JAQMJHY 9+0KYxcjF4eQwBFGiTn3OlghnMWMEhOnfWXqYuTgYBOwkOj+pw3SICKgLHFux11mkDCzgLrE 1cVBIKawQJXEyWd1EBXVEpuPX2SDsK0k5p69wg5iswioSiz8doUFxOYVsJa4dGMWmC0kkC2x dc09sBpOoPo9P2aD2YwCYhLfT61hArGZBcQlbj2ZzwRxsoDEkj3nmSFsUYmXj/+xgtiiAnoS +/59hXpLUaL9aQMjRK+OxILdn9ggbGuJl2eamCFsbYllC18zQ9wjKHFy5hOWCYzis5Csm4Wk fRaS9llI2mchaV/AyLqKUbQ4tbg4N93ISC+1KDO5uDg/Ty8vtWQTIzDSDm75bbWD8eBzx0OM AhyMSjy8X/8qRwqxJpYVV+YeYpTgYFYS4T38HSjEm5JYWZValB9fVJqTWnyIUZqDRUmc12Hf hQghgfTEktTs1NSC1CKYLBMHp1QDY+/tnbpfJi12ianeOrNVJG5r/U7p/duivvap6rFwry4/ cEZs1oWUifoLuD2d3r7RrnHQ23ExL3AhdzVr6mSb0z+kahrn34lob76xcbGOUmqSnPX/rhy+ jY3KsxJ3vQmPuaLZ+uyK6nW+1eueFJ36tPhk5UKj2ckWGkJPrwnv574VmWzyd+XvdUosxRmJ hlrMRcWJAChvb/awAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/YuT1l-iVsJUTluc5Tfcfm0fOsmE>
Subject: Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 May 2017 09:52:13 -0000

Hi Cullen,

Please note that the PR has been updated.

Regards,

Christer


On 23/05/17 05:39, "Cullen Jennings" <fluffy@iii.ca> wrote:

>
>> On May 16, 2017, at 12:43 AM, Christer Holmberg
>><christer.holmberg@ericsson.com> wrote:
>> 
>> The pull request based on the WGLC comments from Roman S and Martin T,
>> suggests text saying that if an offerer receives ClientHello it must not
>> send ServerHello until it has received the answer (that carries the
>> fingerprint associated with the DTLS association).
>
>I strongly disagree with adding this at this level. Consider for example
>an endpoint that does not do ICE. Will you also wait until the identity
>checks are complete to check that the fingerprint is valid and not
>inserted by a MITM? That might make sense for WebRTC but it is something
>specified at a much higher system level than here. This should just be a
>building block that allows systems to use dtls-sdp as they see fit
>instead of trying to mandate how it will be used at a higher level.
>
>