Re: [rtcweb] Encryption mandate (and offer/answer)

Jonathan Lennox <jonathan@vidyo.com> Wed, 07 September 2011 20:16 UTC

Return-Path: <jonathan@vidyo.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A289721F8B35 for <rtcweb@ietfa.amsl.com>; Wed, 7 Sep 2011 13:16:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.428
X-Spam-Level:
X-Spam-Status: No, score=-2.428 tagged_above=-999 required=5 tests=[AWL=0.171, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yGSWmebOo0dL for <rtcweb@ietfa.amsl.com>; Wed, 7 Sep 2011 13:16:44 -0700 (PDT)
Received: from mxout.myoutlookonline.com (mxout.myoutlookonline.com [64.95.72.241]) by ietfa.amsl.com (Postfix) with ESMTP id F374221F8AD2 for <rtcweb@ietf.org>; Wed, 7 Sep 2011 13:16:39 -0700 (PDT)
Received: from mxout.myoutlookonline.com (localhost [127.0.0.1]) by mxout.myoutlookonline.com (Postfix) with ESMTP id 5E33D416DE9; Wed, 7 Sep 2011 16:18:21 -0400 (EDT)
X-Virus-Scanned: by SpamTitan at mail.lan
Received: from HUB015.mail.lan (unknown [10.110.2.1]) by mxout.myoutlookonline.com (Postfix) with ESMTP id DB7A2416C14; Wed, 7 Sep 2011 16:18:07 -0400 (EDT)
Received: from BE235.mail.lan ([10.110.32.235]) by HUB015.mail.lan ([10.110.17.15]) with mapi; Wed, 7 Sep 2011 16:18:07 -0400
From: Jonathan Lennox <jonathan@vidyo.com>
To: Randell Jesup <randell-ietf@jesup.org>
Date: Wed, 07 Sep 2011 16:18:06 -0400
Thread-Topic: [rtcweb] Encryption mandate (and offer/answer)
Thread-Index: Acxtm0DqCbR+QDMlQjm0HYi+uYT9jA==
Message-ID: <BE60FA11-8FFF-48E5-9F83-4D84A7FBE2BE@vidyo.com>
References: <A444A0F8084434499206E78C106220CA0B00FDB08B@MCHP058A.global-ad.net> <89177AB2-F721-47E4-8471-2180EDA10615@voxeo.com> <A444A0F8084434499206E78C106220CA0B00FDB34D@MCHP058A.global-ad.net> <496EE152-41F2-49AB-A136-05735FE5A9F9@voxeo.com><101C6067BEC68246B0C3F6843BCCC1E31018BF6BE2@MCHP058A.global-ad.net> <4E540FE2.7020605@alcatel-lucent.com> <2E239D6FCD033C4BAF15F386A979BF5106423F@sonusinmail02.sonusnet.com> <4E6595E7.7060503@skype.net> <4E661C83.5000103@alcatel-lucent.com> <2E239D6FCD033C4BAF15F386A979BF510F086B@sonusinmail02.sonusnet.com> <4E666926.8050705@skype.net> <43A0D702-1D1F-4B4E-B8E6-C9F1A06E3F8A@edvina.net> <033458F56EC2A64E8D2D7B759FA3E7E7020E64DC@sonusmail04.sonusnet.com> <E4EC1B17-0CC4-4F79-96DD-84E589FCC4F0@edvina.net> <4E67C3F7.7020304@jesup.org>
In-Reply-To: <4E67C3F7.7020304@jesup.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] Encryption mandate (and offer/answer)
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Sep 2011 20:16:44 -0000

On Sep 7, 2011, at 3:20 PM, Randell Jesup wrote:
> You could make forced-encryption the default, and allow the application 
> control over whether to allow it is turned off for specific cases, like 
> a PSTN call, or under the server's control.  Signalling is secure, so it 
> could even use a direct optional downgrade from SAVP* to AVP* (i.e. 
> similar to the best-effort-strp draft)

This has implications for the parallel thread about the use of SDP offer/answer.

The solution MMUSIC has standardized for best-effort SRTP is SDP CapNeg, RFC 5939.  Do we want to require CapNeg support in browsers?

--
Jonathan Lennox
jonathan@vidyo.com