Re: [rtcweb] What is consent?

Harald Alvestrand <harald@alvestrand.no> Tue, 11 September 2012 16:49 UTC

Return-Path: <harald@alvestrand.no>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E530121F8773 for <rtcweb@ietfa.amsl.com>; Tue, 11 Sep 2012 09:49:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.599
X-Spam-Level:
X-Spam-Status: No, score=-110.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0f28UYT-9ysH for <rtcweb@ietfa.amsl.com>; Tue, 11 Sep 2012 09:49:46 -0700 (PDT)
Received: from eikenes.alvestrand.no (eikenes.alvestrand.no [158.38.152.233]) by ietfa.amsl.com (Postfix) with ESMTP id 5023921F871D for <rtcweb@ietf.org>; Tue, 11 Sep 2012 09:49:46 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id 0E57239E194 for <rtcweb@ietf.org>; Tue, 11 Sep 2012 18:49:45 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at eikenes.alvestrand.no
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sbLiCFqFVaGl for <rtcweb@ietf.org>; Tue, 11 Sep 2012 18:49:44 +0200 (CEST)
Received: from [IPv6:2001:470:de0a:27:221:6aff:fe8f:cf14] (unknown [IPv6:2001:470:de0a:27:221:6aff:fe8f:cf14]) by eikenes.alvestrand.no (Postfix) with ESMTPSA id 10B2839E173 for <rtcweb@ietf.org>; Tue, 11 Sep 2012 18:49:44 +0200 (CEST)
Message-ID: <504F6BB6.9050301@alvestrand.no>
Date: Tue, 11 Sep 2012 18:49:58 +0200
From: Harald Alvestrand <harald@alvestrand.no>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:15.0) Gecko/20120827 Thunderbird/15.0
MIME-Version: 1.0
To: rtcweb@ietf.org
References: <CABkgnnXAPZ5BN=CUwYdEpHKbCLBxctqpONL==QWf_WwgrNEK_A@mail.gmail.com> <CABcZeBNnoQwJu1MYSW=6q6pkrgXSPSUtVyOsngrPP6b8GaegdQ@mail.gmail.com> <CABkgnnUNhka8OJsiNCV5iOvU_cGyvt_y8=DN6qnud3Xr-dy1iQ@mail.gmail.com> <CABcZeBNddHgHnkZ5b2N4i-np3WuY51f6WHkBdT5mHBsieLMDow@mail.gmail.com> <CABkgnnVcf06uXPznn38VGGSi6u6brH_4j30cZjbF_YYj7zg9zA@mail.gmail.com>
In-Reply-To: <CABkgnnVcf06uXPznn38VGGSi6u6brH_4j30cZjbF_YYj7zg9zA@mail.gmail.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: Re: [rtcweb] What is consent?
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Sep 2012 16:49:47 -0000

On 09/11/2012 06:34 PM, Martin Thomson wrote:
> On 11 September 2012 09:22, Eric Rescorla <ekr@rtfm.com> wrote:
>> I'm really not following this.
>>
>> Responses from the server need to *contain* the MESSAGE-INTEGRITY
>> field and otherwise are not taken as evidence of consent. This field can
>> only be generated by a server that has the ICE credentials. So, obviously,
>> a legacy STUN server won't generate that.
> It's clear that I'm just being thick.
>
> The STUN server (legacy or otherwise) won't have a password and wont
> generate MESSAGE-INTEGRITY.
>
> I apologise for wasting your (and everyone else's) time.
The terms might have gotten confused, since STUN is used in two modes:

- With a STUN server, to identify reflexive addresses
- With a peer, to verify ability to communicate, and to verify continued 
consent.

We don't want to mandate credentials for the first one.
We do want to mandate credentials for the second.

> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb