Re: [rtcweb] URI schemes for TURN and STUN

Harald Alvestrand <harald@alvestrand.no> Sun, 30 October 2011 04:41 UTC

Return-Path: <harald@alvestrand.no>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1CCC411E8083; Sat, 29 Oct 2011 21:41:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.524
X-Spam-Level:
X-Spam-Status: No, score=-110.524 tagged_above=-999 required=5 tests=[AWL=0.075, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OmeszXy7rRcr; Sat, 29 Oct 2011 21:41:01 -0700 (PDT)
Received: from eikenes.alvestrand.no (eikenes.alvestrand.no [158.38.152.233]) by ietfa.amsl.com (Postfix) with ESMTP id 2198D11E8082; Sat, 29 Oct 2011 21:41:01 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id 3228139E162; Sun, 30 Oct 2011 05:41:00 +0100 (CET)
X-Virus-Scanned: Debian amavisd-new at eikenes.alvestrand.no
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i6lPh-Opdjpx; Sun, 30 Oct 2011 05:40:59 +0100 (CET)
Received: from [192.168.6.21] (unknown [24.104.44.194]) by eikenes.alvestrand.no (Postfix) with ESMTPS id 05BD939E088; Sun, 30 Oct 2011 05:40:57 +0100 (CET)
Message-ID: <4EACD558.1050003@alvestrand.no>
Date: Sat, 29 Oct 2011 21:40:56 -0700
From: Harald Alvestrand <harald@alvestrand.no>
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.23) Gecko/20110921 Thunderbird/3.1.15
MIME-Version: 1.0
To: Marc Petit-Huguenin <petithug@acm.org>
References: <4EAC6BF4.2000604@alvestrand.no> <CALiegf=f4kFzyDLWK+Y5vbuCEJFXX590+VuZ4bbnHZnvX0CoBA@mail.gmail.com> <4EAC8AE0.3020307@acm.org>
In-Reply-To: <4EAC8AE0.3020307@acm.org>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Cc: Keith Moore <moore@cs.utk.edu>, "rtcweb@ietf.org" <rtcweb@ietf.org>, Ned Freed <ned.freed@mrochek.com>, Behave WG <behave@ietf.org>
Subject: Re: [rtcweb] URI schemes for TURN and STUN
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 30 Oct 2011 04:41:02 -0000

On 10/29/2011 04:23 PM, Marc Petit-Huguenin wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 10/29/2011 03:36 PM, Iñaki Baz Castillo wrote:
>> 2011/10/29 Harald Alvestrand<harald@alvestrand.no>:
>>> - I do not think it's appropriate to use "turn" and "turns" for indicating
>>> transport. Polluting the URI namespace with more configuration parameters in
>>> the form of trailing "s" is a Bad Thing.
>> But there should be some way to indicate that a TURN server listens in
>> TLS, right?
>>
> We should continue this discussion in BEHAVE, but I would like to ask the OP to
> send a pointer on the RFC or discussion that says that using a trailing "s" to
> indicate security is a bad thing.
I'll have to forward this question to the apps ADs of a few years ago 
about whether there's documentation for it. It does not seem to have 
been captured in an RFC that I can find; discussion was in the 
~2000-2005 timeframe.

The short version, from memory: Doing "s" locks you into one and exactly 
one security scheme, and prevents you from saying anything about the 
requisite parameters for that scheme, while using AUTH parameters such 
as POP or in-band negotiation such as IMAP  are much more flexible 
approaches.


> Thanks.
>
> - -- 
> Marc Petit-Huguenin
> Personal email: marc@petit-huguenin.org
> Professional email: petithug@acm.org
> Blog: http://blog.marc.petit-huguenin.org
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.11 (GNU/Linux)
>
> iEYEARECAAYFAk6sit4ACgkQ9RoMZyVa61dhpgCfZv+XuDhAljo3N0s33zbh6l0E
> aWAAmwUP2mvcZiY9BLB5BAsjoe6OULMl
> =yx3i
> -----END PGP SIGNATURE-----
>