Re: [rtcweb] Fwd: New Version Notification for draft-uberti-rtcweb-turn-rest-00.txt

"Muthu Arul Mozhi Perumal (mperumal)" <> Mon, 08 July 2013 05:52 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 1DDDE11E818A for <>; Sun, 7 Jul 2013 22:52:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -9.998
X-Spam-Status: No, score=-9.998 tagged_above=-999 required=5 tests=[AWL=0.599, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id s9SjnK3QeQj5 for <>; Sun, 7 Jul 2013 22:52:51 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 781AB11E8188 for <>; Sun, 7 Jul 2013 22:52:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple;;; l=18276; q=dns/txt; s=iport; t=1373262771; x=1374472371; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=0ZIYy7cGpyI0I9++Wj7LtebQYcTd5aYatpLmgkXleFE=; b=GqPmS24e6YuRSoeXlYjZhpgCTUw3KzAyvHE4F0P09solOp4fDMiD1Dmt yJsJkUWpUcKkXVVodkKktrhg4JP0Y4xMgcwI5ohnz74XtMZhHeVE7vHAb dJfvLYKtGJm/vvS+vWspArR9wiMmMGmdQUEiWUKxOpKMYNfLMYnSGGMVh U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos; i="4.87,1016,1363132800"; d="scan'208,217"; a="232029975"
Received: from ([]) by with ESMTP; 08 Jul 2013 05:52:50 +0000
Received: from ( []) by (8.14.5/8.14.5) with ESMTP id r685qoih018266 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 8 Jul 2013 05:52:50 GMT
Received: from ([]) by ([]) with mapi id 14.02.0318.004; Mon, 8 Jul 2013 00:52:50 -0500
From: "Muthu Arul Mozhi Perumal (mperumal)" <>
To: Justin Uberti <>, "" <>
Thread-Topic: [rtcweb] Fwd: New Version Notification for draft-uberti-rtcweb-turn-rest-00.txt
Thread-Index: AQHOe5MnptNwIaIknUKCiV7zsZZ7FplaO4gA
Date: Mon, 8 Jul 2013 05:52:49 +0000
Message-ID: <>
References: <> <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
x-originating-ip: []
Content-Type: multipart/alternative; boundary="_000_E721D8C6A2E1544DB2DEBC313AF54DE224183578xmbrcdx02ciscoc_"
MIME-Version: 1.0
Subject: Re: [rtcweb] Fwd: New Version Notification for draft-uberti-rtcweb-turn-rest-00.txt
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 08 Jul 2013 05:52:57 -0000

Hi Justin,

A few quick comments:
1) The primary advantage of the proposed mechanism seems not requiring any interaction between the web service and the TURN service in order for the TURN service to grant TURN credentials in the HTTP response -- this absence of interaction isn't evident on a first read. A diagram showing the client, web service, TURN service and the messages exchanged would be helpful.

|If desired, the TURN server can optionally verify that the parsed
|user id value corresponds to a currently valid user of an external
|service (e.g. is currently logged in to the web app that is making
|use of TURN).  This requires proprietary communication between the
|TURN server and external service on each ALLOCATE request, so this
|usage is not recommended for typical applications.  If this external
|verification fails, it SHOULD reject the request with a 401
|(Unauthorized) error.

Was the intention of putting "not recommended" having a normative statement? If not, it would be better to change it to "no needed".

3) There is no text describing how the timestamp encoded in the UNSERNAME attribute of the ALLOCAE requested could be protected.

4) draft-reddy-behave-turn-auth describes the issues with TURN authentication and draft-uberti-rtcweb-turn-rest looks like one possible solution. Looks both could reference each other.


From: [] On Behalf Of Justin Uberti
Sent: Monday, July 08, 2013 9:55 AM
Subject: [rtcweb] Fwd: New Version Notification for draft-uberti-rtcweb-turn-rest-00.txt

Just uploaded a 00 version of a spec for requesting time-limited TURN credentials for WebRTC apps. Would like to get 10 minutes of agenda time to present this in Berlin.

---------- Forwarded message ----------
From: <<>>
Date: Mon, Jul 8, 2013 at 12:15 AM
Subject: New Version Notification for draft-uberti-rtcweb-turn-rest-00.txt
To: Justin Uberti <<>>

A new version of I-D, draft-uberti-rtcweb-turn-rest-00.txt
has been successfully submitted by Justin Uberti and posted to the
IETF repository.

Filename:        draft-uberti-rtcweb-turn-rest
Revision:        00
Title:           A REST API For Access To TURN Services
Creation date:   2013-07-08
Group:           Individual Submission
Number of pages: 7

   This document describes a proposed standard REST API for obtaining
   access to TURN services via ephemeral (i.e. time-limited)
   credentials.  These credentials are vended by a web service over
   HTTP, and then supplied to and checked by a TURN server using the
   standard TURN protocol.  The usage of ephemeral credentials ensures
   that access to the TURN server can be controlled even if the
   credentials can be discovered by the user, as is the case in WebRTC
   where TURN credentials must be specified in Javascript.

The IETF Secretariat