[P2PSIP] Signature validation for TURN-SERVICE kind

Marc Petit-Huguenin <petithug@acm.org> Sun, 17 July 2011 17:11 UTC

Return-Path: <petithug@acm.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA4B121F84BC for <p2psip@ietfa.amsl.com>; Sun, 17 Jul 2011 10:11:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.591
X-Spam-Level:
X-Spam-Status: No, score=-102.591 tagged_above=-999 required=5 tests=[AWL=0.009, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UYs5wdvYeNec for <p2psip@ietfa.amsl.com>; Sun, 17 Jul 2011 10:11:24 -0700 (PDT)
Received: from implementers.org (implementers.org [IPv6:2604:3400:dc1:41:216:3eff:fe5b:8240]) by ietfa.amsl.com (Postfix) with ESMTP id 1346121F8429 for <p2psip@ietf.org>; Sun, 17 Jul 2011 10:11:24 -0700 (PDT)
Received: from [IPv6:2001:55c:4c15:5f80:213:d4ff:fe04:3e08] (unknown [IPv6:2001:55c:4c15:5f80:213:d4ff:fe04:3e08]) by implementers.org (Postfix) with ESMTPS id 91B762199E for <p2psip@ietf.org>; Sun, 17 Jul 2011 19:09:36 +0200 (CEST)
Message-ID: <4E2317B6.4090901@acm.org>
Date: Sun, 17 Jul 2011 10:11:18 -0700
From: Marc Petit-Huguenin <petithug@acm.org>
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.18) Gecko/20110626 Iceowl/1.0b2 Icedove/3.1.11
MIME-Version: 1.0
To: P2PSIP WG <p2psip@ietf.org>
X-Enigmail-Version: 1.1.2
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Subject: [P2PSIP] Signature validation for TURN-SERVICE kind
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 17 Jul 2011 17:11:24 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

When storing a TURN-SERVICE kind, the storing peer cannot count on having the
certificate used to sign the value available locally, because the
CERTIFICATE_BY_NODE and CERTIFICATE_BY_USER kinds will be stored in a different
peer.

Is the intent that the storing peer remotely fetch the certificate for the
validation or should it fail when the certificate is not sent in the
certificates field of the SecurityBlock?

Note that if the request should fail, then it is a problem with replications as
there is very little chance to have the right certificate in the SecurityBlock
when the value is replicated.

- -- 
Marc Petit-Huguenin
Personal email: marc@petit-huguenin.org
Professional email: petithug@acm.org
Blog: http://blog.marc.petit-huguenin.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk4jF7QACgkQ9RoMZyVa61d/mQCgnL3vndPpYAJds03IvXnYZprE
MmsAoITz6U97WHeyIone4md7hwYFIxNW
=BPUG
-----END PGP SIGNATURE-----