[rtcweb] Use case change request: Identity in multiuser calls

Harald Alvestrand <harald@alvestrand.no> Wed, 10 August 2011 14:15 UTC

Return-Path: <harald@alvestrand.no>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 85E8221F8AED for <rtcweb@ietfa.amsl.com>; Wed, 10 Aug 2011 07:15:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mlgh89rALPrX for <rtcweb@ietfa.amsl.com>; Wed, 10 Aug 2011 07:15:48 -0700 (PDT)
Received: from eikenes.alvestrand.no (eikenes.alvestrand.no [158.38.152.233]) by ietfa.amsl.com (Postfix) with ESMTP id E3F8F21F8ABC for <rtcweb@ietf.org>; Wed, 10 Aug 2011 07:15:47 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id DA87F39E155 for <rtcweb@ietf.org>; Wed, 10 Aug 2011 16:15:07 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at eikenes.alvestrand.no
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5tu5+w2k7C40 for <rtcweb@ietf.org>; Wed, 10 Aug 2011 16:15:07 +0200 (CEST)
Received: from hta-dell.lul.corp.google.com (62-20-124-50.customer.telia.com [62.20.124.50]) by eikenes.alvestrand.no (Postfix) with ESMTPS id 2D25439E03C for <rtcweb@ietf.org>; Wed, 10 Aug 2011 16:15:07 +0200 (CEST)
Message-ID: <4E4292B2.8000904@alvestrand.no>
Date: Wed, 10 Aug 2011 16:16:18 +0200
From: Harald Alvestrand <harald@alvestrand.no>
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.18) Gecko/20110617 Thunderbird/3.1.11
MIME-Version: 1.0
To: rtcweb@ietf.org
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: [rtcweb] Use case change request: Identity in multiuser calls
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Aug 2011 14:15:48 -0000

In draft-ietf-rtcweb-use-cases-and-requirements, I would like to extend 
one part of the scenario "4.3.3 Video conferencing system with central 
server".

I would like to add one more paragraph:

"All participant are authenticated by the central server, and authorized 
to connect to the central server. The participants are identified to 
each other by the central server, and the participants do not have 
access to each others' credentials such as e-mail addresses or login IDs".

This is necessary in order to drive use cases that resemble Google 
Hangout, where it is a requirement that people are able to participate 
without disclosing their Google login IDs to each other.
(in the particular case of Hangout, the display name on their profile 
*is* disclosed ... but that's a different matter)

The reason I think this is important is that it feeds directly into the 
discussion of what WebRTC needs to authorize: The final source or 
destination of media, or the identity of the handler at the first hop. 
In at least the case of Hangouts, the requirement is to *not* authorize 
the final source or destination.

Not sure yet how to formulate that as a requirement, and not sure yet if 
it applies to the cases without a central server, such as 4.2.6. We may 
have to decide.

                         Harald