Re: [Perc] Magnus Westerlund's Discuss on draft-ietf-perc-double-10: (with DISCUSS and COMMENT)
Magnus Westerlund <magnus.westerlund@ericsson.com> Thu, 29 August 2019 14:19 UTC
Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: perc@ietfa.amsl.com
Delivered-To: perc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD722120071; Thu, 29 Aug 2019 07:19:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level:
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JX_5lJFnQgTS; Thu, 29 Aug 2019 07:19:23 -0700 (PDT)
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (mail-eopbgr140080.outbound.protection.outlook.com [40.107.14.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE03812004A; Thu, 29 Aug 2019 07:19:22 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=h5r1GZ8afE9eCVdCLwP0BuiqmgMMvfTti2wof9EKvxYk5NvQKNpEyDqEckG2qq9SdMo3T9vTgSv+2z+RN/6mOP0dOqW0nfNIujWZqp1MxFZg0UIHSJYOewxG4zV/4ZUy5rMjqAZhD0aEiyhacL1uYYx1F+bdWjgYPJBElXfmcYRatmu3f5Fh8xp+6dtrowtZOau2+gtMJdzTVYAPWjRWnkdFFcV6FvGUqRW7vg2WtI8rTHilatPWyjcYrGSZ9yetWg3Eb8Dk4O2Ayg1Pt7EryVFWCfU4c+LJS/ZnyfiHFmdg8gNKqG5T4IkG/awm5ephUxMaxX87oq1q95MyrbWnFg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=UI1YdICF1U8TACOPif1AoIY4PM6RETfcAPD8un9e8OM=; b=f4BEtwuJHo5fXcLi3yaDBi2xnFLqH7dm5FBeYsCQAbXKKliSwFJRdJuwNmL+43WZqsv2vUHGmEXCvolxQV+1f0uAPPyTm75wwDFQHsFj+o+/41sdgurXjHl9pLtzmfyHwYrS/GEOd4eQ9oKfHSBwAjMyvYeXkeIFabousEy/pNhXHNNLeXMXxkQax/SpvQv4Le+LmmwrWaee1C3ufN0aa75ihP/Lhg8s04PS//VJn4KVFpXwF0bxTx9I/lE/mAkbXwAx6t4qrXWkG+r2dksYviatYxhZKP92cGqaJbeQKJvrMEXEcHreo+K5tCuPP35ehJ7onoNXzf+VJSrp/NtEdg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=UI1YdICF1U8TACOPif1AoIY4PM6RETfcAPD8un9e8OM=; b=USzP462+UK47sNCKpNl+Pa2ovbVSAdI6iS6NcGtp8Zn6aNSzKxm4u7fuFmfAgM1BYJljwDUEzum2eupLee0bSeIO7o0RPsXRklEfzgwRqqG+NC/OHkP92TMmgYM4F+2RFYTTowQ+a47cO/Lp4aVjIO3tePMaeJmg47CRSdi4OAc=
Received: from DB7PR07MB5736.eurprd07.prod.outlook.com (20.177.194.155) by DB7PR07MB5564.eurprd07.prod.outlook.com (20.178.46.219) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2220.15; Thu, 29 Aug 2019 14:19:20 +0000
Received: from DB7PR07MB5736.eurprd07.prod.outlook.com ([fe80::a935:4edd:29a2:9772]) by DB7PR07MB5736.eurprd07.prod.outlook.com ([fe80::a935:4edd:29a2:9772%6]) with mapi id 15.20.2241.000; Thu, 29 Aug 2019 14:19:20 +0000
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
To: "rlb@ipv.sx" <rlb@ipv.sx>
CC: "fluffy@iii.ca" <fluffy@iii.ca>, "perc@ietf.org" <perc@ietf.org>, "suhasietf@gmail.com" <suhasietf@gmail.com>, "iesg@ietf.org" <iesg@ietf.org>, "perc-chairs@ietf.org" <perc-chairs@ietf.org>, "draft-ietf-perc-double@ietf.org" <draft-ietf-perc-double@ietf.org>
Thread-Topic: [Perc] Magnus Westerlund's Discuss on draft-ietf-perc-double-10: (with DISCUSS and COMMENT)
Thread-Index: AQHVC85uMqFQ5/RAl0Cyrib7XAHyUKZvpqsAgHzvMNCAAIv1gIARSUAAgBQbigCAAEMlgIAACBkA
Date: Thu, 29 Aug 2019 14:19:20 +0000
Message-ID: <b3d6130cd01a0a9f6b2c4b94df673c7fbf81a089.camel@ericsson.com>
References: <155800082724.19580.16483563575859435866.idtracker@ietfa.amsl.com> <65737EA1-49AF-4EB9-AD1F-25157B3F010D@iii.ca> <HE1PR0701MB25220714DB8E5AE970E0FDFA95DA0@HE1PR0701MB2522.eurprd07.prod.outlook.com> <CAL02cgTf9sMonRFG1qi9pLxuK8ruvxUStdcju8JU_9+5Kty53w@mail.gmail.com> <CAMRcRGT-izdwyuLX+kiPL5q5TnhoTKGw_9OJSvkDQo59JujS6w@mail.gmail.com> <5cec79c71d859aa95e352824320ad261f8525916.camel@ericsson.com> <CAL02cgRRckXWtuA_dnOLz7mvWEeDetW+2dqq5+sDBraDFLqqZg@mail.gmail.com>
In-Reply-To: <CAL02cgRRckXWtuA_dnOLz7mvWEeDetW+2dqq5+sDBraDFLqqZg@mail.gmail.com>
Accept-Language: sv-SE, en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=magnus.westerlund@ericsson.com;
x-originating-ip: [192.176.1.84]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: afbb8f74-2f70-4777-b8a1-08d72c8be222
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600166)(711020)(4605104)(1401327)(2017052603328)(49563074)(7193020); SRVR:DB7PR07MB5564;
x-ms-traffictypediagnostic: DB7PR07MB5564:
x-microsoft-antispam-prvs: <DB7PR07MB5564DC8AD059E7A5E5A0834F95A20@DB7PR07MB5564.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-forefront-prvs: 0144B30E41
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(136003)(39860400002)(346002)(396003)(376002)(366004)(199004)(189003)(13464003)(186003)(25786009)(81156014)(316002)(486006)(11346002)(3846002)(26005)(1730700003)(76116006)(66616009)(64756008)(66446008)(66476007)(14444005)(81166006)(14454004)(66556008)(66946007)(2906002)(71190400001)(8676002)(2616005)(256004)(6116002)(71200400001)(6246003)(478600001)(99936001)(305945005)(229853002)(4326008)(7736002)(6306002)(5640700003)(6512007)(6506007)(2351001)(76176011)(53936002)(6436002)(6916009)(66066001)(5660300002)(102836004)(2501003)(476003)(6486002)(446003)(36756003)(8936002)(118296001)(53546011)(99286004)(91956017)(966005)(54906003)(44832011)(86362001); DIR:OUT; SFP:1101; SCL:1; SRVR:DB7PR07MB5564; H:DB7PR07MB5736.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: WFTKq+vZKp28YoDdXCu1g0Emzpq7bec3wzaq86bhclRJjYr22YA0lm4NzhIbuTW83EH8wZIr7ReGDmV4p8C26lCl49T4gozuRo/FqWJXNexG2KqOyBi4iEmZuDs1ww0v18OG77CHDI6cj4RQ+BxUwDGH9vQkGSnwUpxLjmkTK/fSMat69Dr87oT81eWIHpitrJbsjQ7rFaUtUlHOdxWiJwsMTiuRVqoaixi3m9mgADlYi6evLmc3DFaVn0QwieIWnQYkd569AcRLEtGb/DKgVah1aLQxyt/vsPxjRrCNckkttL8pVEGHzllxVvWmo4EgoxW59+Bp480AqJ+1joZpP3MVf59kJDgSakNZLYbFMukak94gyYNCu+8dYO4SMoybb+0FjgHzE6Ut7LFbYsLaGqhTX2USkl96Z6UPZ5WBSgw=
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; micalg="sha-256"; protocol="application/x-pkcs7-signature"; boundary="=-cqTlAM2FBDeaNtMvBdY/"
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: afbb8f74-2f70-4777-b8a1-08d72c8be222
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Aug 2019 14:19:20.1377 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: sKksnWT4Nn9UcDOCWuuoJxtCSK7aocpCAgimtbir+CZ7nlv3halid4Hghg7yEMr87XNiTBqKoPEyFHMApYJCjgPbXRmT9e5/GuN7s9m8GjE=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB7PR07MB5564
Archived-At: <https://mailarchive.ietf.org/arch/msg/perc/6ydihdIM0v8joDTJ20PEOdBiJEI>
Subject: Re: [Perc] Magnus Westerlund's Discuss on draft-ietf-perc-double-10: (with DISCUSS and COMMENT)
X-BeenThere: perc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Privacy Enhanced RTP Conferencing <perc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perc>, <mailto:perc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/perc/>
List-Post: <mailto:perc@ietf.org>
List-Help: <mailto:perc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perc>, <mailto:perc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Aug 2019 14:19:27 -0000
Hi, I will clear when the new version is available or an RFC-editor note to this affect has been included. Cheers Magnus On Thu, 2019-08-29 at 09:50 -0400, Richard Barnes wrote: > Easy enough. I think RFC 3711 is clear enough, but if you want it to > be more explicit, so it shall be. I just copied over the language > from 3711. > > https://github.com/ietf/perc-wg/pull/174 > > > > On Thu, Aug 29, 2019 at 5:50 AM Magnus Westerlund < > magnus.westerlund@ericsson.com> wrote: > > Hi, > > Hi, > > > > > > Back from vacation. > > > > No Richards explanation doesn't help. Section 5.1 contains a > > normative > > description of how to create a synthetic packet. That description > > is > > not expplicit that the padding shall be part of the information > > that is > > included. Thus, implicitly the described procedure forbidds > > padding. > > Per RFC 3550 the padding is not part of the payload thus the need > > for > > being explicit about that the padding is to be included here. > > > > My suggestion is still that the following bullet: > > > > * Payload: The RTP payload of the original packet > > > > Is changes to be explicit that padding is to be included: > > > > "* Payload: The RTP payload (including > > padding) of the original packet” > > > > Any other way that makes it explcit that the origianl packets > > padding > > is to be included is fine by me. But it does need to be explcit. > > > > Cheers > > > > Magnus > > > > On Fri, 2019-08-16 at 07:46 -0700, Suhas Nandakumar wrote: > > > Hey Magnus > > > > > > Wondering if Richard's response answers your question? > > > > > > Thanks > > > Suhas > > > > > > On Mon, Aug 5, 2019 at 7:48 AM Richard Barnes <rlb@ipv.sx> wrote: > > > > Hey Magnus, > > > > > > > > Sorry, should have responded on Point 1. I think you're just > > > > mistaken on that point. Padding is included within the inner > > > > encryption. The double transform is an SRTP transform like any > > > > other; outside of the SRTP stack, there is no "inner" or > > "outer", > > > > just the same old protect and unprotect. So padding works the > > same > > > > as it does with any other SRTP transform. > > > > > > > > Was there some text in the document that gave you the > > impression > > > > that padding was not included under the inner encryption? The > > only > > > > mention of padding I see in the document is in the figure in > > > > Appendix A [1], where the padding is correctly shown to be > > within > > > > the inner encryption. Happy to clarify if you have some > > > > suggestions for how. > > > > > > > > --Richard > > > > > > > > [1] > > > > > > https://tools.ietf.org/html/draft-ietf-perc-double-11#appendix-A > > > > > > > > On Mon, Aug 5, 2019 at 2:32 AM Magnus Westerlund < > > > > magnus.westerlund@ericsson.com> wrote: > > > > > Hi, > > > > > > > > > > Sorry, I missed when this update was submitted, thanks for > > the > > > > > reminder. > > > > > > > > > > The new version addresses most of my discuss, but missed to > > do > > > > > anything about point 1 below. > > > > > > > > > > Otherwise it appears to address my discuss points. How do you > > > > > want to resolve it? > > > > > > > > > > Cheers > > > > > > > > > > Magnus Westerlund > > > > > > > > > > > -----Original Message----- > > > > > > From: Cullen Jennings <fluffy@iii.ca> > > > > > > Sent: den 17 maj 2019 20:34 > > > > > > To: Magnus Westerlund <magnus.westerlund@ericsson.com> > > > > > > Cc: The IESG <iesg@ietf.org>; perc-chairs@ietf.org; draft- > > ietf- > > > > > perc- > > > > > > double@ietf.org; suhasietf@gmail.com; perc@ietf.org > > > > > > Subject: Re: [Perc] Magnus Westerlund's Discuss on draft- > > ietf- > > > > > perc-double- > > > > > > 10: (with DISCUSS and COMMENT) > > > > > > > > > > > > > > > > > > > > 1. Section 5.1: > > > > > > > > > > > > > > To me it appears that one fundamental security flaw > > exists in > > > > > the > > > > > > > definition of the inner encryption. That is the fact that > > RTP > > > > > padding > > > > > > > is not included into the inner encrypted part. This > > prevents > > > > > the > > > > > > > application of RTP padding to prevent the potential > > privacy > > > > > leakage > > > > > > > that "Guidelines for the Use of Variable Bit Rate Audio > > with > > > > > Secure > > > > > > > RTP" (RFC 6562) documents. To prevent this type of > > > > > information leakage > > > > > > > and other privacy preserving operations based on applying > > RTP > > > > > padding > > > > > > > it would be necessary to include the RTP padding into the > > > > > inner > > > > > > > encrypted envelope. Appendix A figure indicates that is > > the > > > > > case, but the > > > > > > process description in 5.1 is not matching that. > > > > > > > > > > > > > > > > > > > So my read of 5.1 is that does this. Clearly we need to > > make > > > > > the text clear > > > > > > that it does that - what part of the 5.1 makes you think > > the > > > > > padding is > > > > > > stripped from the payload ? > > > > > > > > > > > > Perhaps to make it explicitly clear we should change > > > > > > > > > > > > "* Payload: The RTP payload of the original packet” > > > > > > > > > > > > to be > > > > > > > > > > > > "* Payload (including padding) The RTP payload (including > > > > > passing) of the > > > > > > original packet” > > > > > > > > > > > > > > > > > > > > > > > > > > > > > -- Cheers Magnus Westerlund ---------------------------------------------------------------------- Network Architecture & Protocols, Ericsson Research ---------------------------------------------------------------------- Ericsson AB | Phone +46 10 7148287 Torshamnsgatan 23 | Mobile +46 73 0949079 SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com ----------------------------------------------------------------------
- [Perc] Magnus Westerlund's Discuss on draft-ietf-… Magnus Westerlund via Datatracker
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Cullen Jennings
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Magnus Westerlund
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Magnus Westerlund
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Richard Barnes
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Suhas Nandakumar
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Magnus Westerlund
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Richard Barnes
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Magnus Westerlund
- Re: [Perc] Magnus Westerlund's Discuss on draft-i… Richard Barnes