Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?

Christer Holmberg <christer.holmberg@ericsson.com> Mon, 29 May 2017 10:41 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04EA7126E64 for <mmusic@ietfa.amsl.com>; Mon, 29 May 2017 03:41:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level:
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cL_cP9VnBefd for <mmusic@ietfa.amsl.com>; Mon, 29 May 2017 03:41:22 -0700 (PDT)
Received: from sessmg23.ericsson.net (sessmg23.ericsson.net [193.180.251.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62E7F1242F7 for <mmusic@ietf.org>; Mon, 29 May 2017 03:41:22 -0700 (PDT)
X-AuditID: c1b4fb2d-1c9ff70000000d37-f7-592bfacfe89c
Received: from ESESSHC024.ericsson.se (Unknown_Domain [153.88.183.90]) by sessmg23.ericsson.net (Symantec Mail Security) with SMTP id 04.B9.03383.FCAFB295; Mon, 29 May 2017 12:41:20 +0200 (CEST)
Received: from ESESSMB109.ericsson.se ([169.254.9.30]) by ESESSHC024.ericsson.se ([153.88.183.90]) with mapi id 14.03.0339.000; Mon, 29 May 2017 12:41:20 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Martin Thomson <martin.thomson@gmail.com>, Eric Rescorla <ekr@rtfm.com>
CC: "mmusic@ietf.org" <mmusic@ietf.org>
Thread-Topic: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
Thread-Index: AQHSzg+3LES5P8e96kuYQ2NFd1Iy/aH22hkAgAAInQCAAAaQgIAASbSwgAjtDoD//+kCgIABw7QA///NpQCAADbcgP//zwiAAJc8RoAAAA1pgAAA2DgAAAeOUYAAlRl6AA==
Date: Mon, 29 May 2017 10:41:19 +0000
Message-ID: <D551D683.1D429%christer.holmberg@ericsson.com>
References: <D5407B8A.1C98B%christer.holmberg@ericsson.com> <CABcZeBN+91+kf8j599CpdiHu62QoOu4Xbkb5xhEEwSQp_LGxFw@mail.gmail.com> <CAD5OKxsFwbQPK2jz-BnS3Re6df2tU1RzuFgWx1f8xKio6NdJTQ@mail.gmail.com> <CABcZeBNoOaZaotNjz35CT=9Vb8ktHysnp9hZZu4=yK3oz5=2Fw@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B4CBA529B@ESESSMB109.ericsson.se> <D5487BC2.1CF8E%christer.holmberg@ericsson.com> <CABkgnnXzzKMWrPaGq6mho=Dmq7Hjbi_G4Ng1O6LBCTL-1Pt-hA@mail.gmail.com> <D549E2A8.1D08C%christer.holmberg@ericsson.com> <CABkgnnXY+uwW=iPjT3O=TmnYj4CD-PYRYkSMTWc5QiFEVBsNiA@mail.gmail.com> <D549E62B.1D0A3%christer.holmberg@ericsson.com> <CABkgnnWSm0T3n0Lrqx3WCqDmPutLDXtkfwK8Pc+0fYdJa+q=hw@mail.gmail.com> <D54DB2E1.1D299%christer.holmberg@ericsson.com> <CABcZeBN000+Qm=FJpB_6bp8WYQhQ7E84XVYO4bXyby2U-DcWew@mail.gmail.com> <CABkgnnXXCj55+f0pG0_5PeAB0GMi3m4EdgPUFFv2=-07uxb_Yw@mail.gmail.com> <D54DEE22.1D304%christer.holmberg@ericsson.com>
In-Reply-To: <D54DEE22.1D304%christer.holmberg@ericsson.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.7.4.170508
x-originating-ip: [153.88.183.20]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <30D833F9116D634C8CB3EFE6568E530D@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrJIsWRmVeSWpSXmKPExsUyM2J7lO6FX9qRBlOvC1iseH2O3eLamX+M FlOXP2ZxYPbYOesuu8eSJT+ZPCY/bmMOYI7isklJzcksSy3St0vgytg8eR5TQQN3xauTk1ka GP9wdDFyckgImEj8fnuTuYuRi0NI4AijxL4v/UwQzmJGiY97n7N0MXJwsAlYSHT/0wZpEBHw lth3cAIrSJhZQF3i6uIgEFNYoEri5LM6iIpqic3HL7KBTBERmMQo0bT/LitIgkVAVaJv6VVm EJtXwFpi+r9HUHs3sku0dTUxgiQ4BWwk7m54wwJiMwqISXw/tYYJxGYWEJe49WQ+E8TRAhJL 9pxnhrBFJV4+/gd2j6iAnsS7/Z4QYUWJq9OXQ7XqSdyYOoUNwraWmP/oHjuErS2xbOFrqHsE JU7OfMIygVF8FpJts5C0z0LSPgtJ+ywk7QsYWVcxihanFhfnphsZ66UWZSYXF+fn6eWllmxi BEbgwS2/dXcwrn7teIhRgINRiYd3+3PtSCHWxLLiytxDjBIczEoivLcfA4V4UxIrq1KL8uOL SnNSiw8xSnOwKInzOuy7ECEkkJ5YkpqdmlqQWgSTZeLglGpgtLjFeHH9ulhJ64Uq++YKOt67 6eN3a/KDY/FrW14tfn/lq8vZGwo2OdtLPkS1Xv3WeerdibTiWBG2BjVLg64DUYy90cdU7r2Q dnaYodVfV79ANvOaSZ1V/9HUX2I8xv1WggklyzNne04WKXohz+khssBrS+yJTwGubgUGxy4f fqjDJr599REVJZbijERDLeai4kQADaPA0LwCAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/mmusic/cObV7YKX-8v4Oc61KXRw4NXYsfc>
Subject: Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mmusic/>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 10:41:24 -0000

Hi,

I have updated the PR.

The text now says ³complete² instead of ³finalise². In addition, I removed
the text about attacks, and only kept the text saying that media received
before the answer must be considered unauthenticated.

If people are still not happy with the text, I¹d really appreciate some
text.

Regards,

Christer



On 26/05/17 14:32, "mmusic on behalf of Christer Holmberg"
<mmusic-bounces@ietf.org on behalf of christer.holmberg@ericsson.com>
wrote:

>Hi,
>
>You are the DTLS gurus - please suggest changes that makes the text
>correct - and still hopefully keeps Cullen happy :)
>
>Regards,
>
>Christer
>
>
>On 26/05/17 14:01, "Martin Thomson" <martin.thomson@gmail.com> wrote:
>
>>On 26 May 2017 at 20:37, Eric Rescorla <ekr@rtfm.com> wrote:
>>> Also, you say that if you initiate the handshake before the answer
>>> is received you are vulnerable to attacks. What attacks are those?
>>
>>It should be "complete" - on the assumption that a completed handshake
>>leads immediately to using the connection.  Really, it's using the
>>connection (sending or receiving data or using exporters) that puts
>>you at risk, but I don't think that it's worth putting that fine a
>>distinction on it.
>
>_______________________________________________
>mmusic mailing list
>mmusic@ietf.org
>https://www.ietf.org/mailman/listinfo/mmusic