Re: [rtcweb] DTLS, DTLS-SRTP, and 5-tuples

Iñaki Baz Castillo <ibc@aliax.net> Mon, 09 March 2015 13:04 UTC

Return-Path: <ibc@aliax.net>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B9F71A8866 for <rtcweb@ietfa.amsl.com>; Mon, 9 Mar 2015 06:04:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.678
X-Spam-Level:
X-Spam-Status: No, score=-1.678 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-0.7] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ee1gwsj7aVW4 for <rtcweb@ietfa.amsl.com>; Mon, 9 Mar 2015 06:04:04 -0700 (PDT)
Received: from mail-qc0-f170.google.com (mail-qc0-f170.google.com [209.85.216.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 34A621A885D for <rtcweb@ietf.org>; Mon, 9 Mar 2015 06:04:04 -0700 (PDT)
Received: by qcrw7 with SMTP id w7so4625751qcr.8 for <rtcweb@ietf.org>; Mon, 09 Mar 2015 06:04:03 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type:content-transfer-encoding; bh=a6y7UQCEMDt1svbzKb/kUn1l1B8aMK7JAFi2uLMS+yA=; b=KyMTrLV9rKgLWacMIPX0dYtMyflUttTf0lVPognVjJ69F6TGMRf5P7J9dguFOmdqAU fgH/rNxg5w9fnVYqy/CeY2Xa2wvrlTzng7naB41LXEWnraRixi0+/NkB3/6plDFXftWI lHJsdkAYvR2YFRSXO9hN7rwOoOF0Q5ASp/CMxsKbm0L4a9Xqj+zLoe+yuj+yuoWWdwE+ HP7g8Xclo4i6oNS+fe9AuvnTVfIRu6CGQYpPrG58IoTuVduH3pISBUA/2Rlgg3gayP+M B+kDTDxL9Xt9z5oWN8xr6TCWrURAGqRxX0tqrgr6iSLN3IuDDsuMdgvI/Sk/nemUNcZ+ lO7Q==
X-Gm-Message-State: ALoCoQkSQoN6GaX4FrszbUOV9WImWa6u8AVmwjh7SNDmHx0817RMFKraIonYQLj1+KpvA+52wH3/
X-Received: by 10.140.144.11 with SMTP id 11mr11413879qhq.54.1425906243373; Mon, 09 Mar 2015 06:04:03 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.96.200.4 with HTTP; Mon, 9 Mar 2015 06:03:43 -0700 (PDT)
In-Reply-To: <7594FB04B1934943A5C02806D1A2204B1D730203@ESESSMB209.ericsson.se>
References: <54F74B02.1070902@jive.com> <CAD5OKxuWCdgMR5Kxjv9BSwZ3Jm9kGXx9Pi-9FrfsnuQZ_91jAA@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B1D726DC1@ESESSMB209.ericsson.se> <CALiegfkipJhsy7-40+=d9xMUf4RJGdn3_fABL3NN2KuFNvS2BA@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B1D727570@ESESSMB209.ericsson.se> <CALiegfmfvz3NWSjcovGBytiOTbR6kFfyh0vx5cXoMJtytfGzRA@mail.gmail.com> <CAD5OKxsu3D0xHY-zYbDu1hyH_+4=3mWDvW2i98WCVZ+29BpKCw@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B1D728297@ESESSMB209.ericsson.se> <CALiegf=uPN+g546Ucv9s89z14cUTEme55y7B1siXZe97yj7Lig@mail.gmail.com> <E1FE4C082A89A246A11D7F32A95A17828E726EEC@US70UWXCHMBA02.zam.alcatel-lucent.com> <CALiegf=oVWk-8UcbQE2Edh=QSXSRUnSC=X-WMyGpvHYQ9SD1yg@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B1D728BE2@ESESSMB209.ericsson.se> <54FCD3BC.4070900@alum.mit.edu> <F37736EA-2AEE-4022-A813-E21469420038@gmail.com> <7594FB04B1934943A5C02806D1A2204B1D72EE30@ESESSMB209.ericsson.se> <54FD964F.2070105@jive.com> <7594FB04B1934943A5C02806D1A2204B1D73015C@ESESSMB209.ericsson.se> <CALiegfn5HQn_H=hUD0iGKUfKRmf0e_Pv=4-GoRFUA=QTfkvYiQ@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B1D730203@ESESSMB209.ericsson.se>
From: Iñaki Baz Castillo <ibc@aliax.net>
Date: Mon, 09 Mar 2015 14:03:43 +0100
Message-ID: <CALiegfmwqoNb1wH3cTkVWHgL4P2MjhhL3hpZK78Gb0LMjq2oOQ@mail.gmail.com>
To: Christer Holmberg <christer.holmberg@ericsson.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/rtcweb/uP6Wm-9wW8Rua2a2SV_aSK-BKpA>
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>
Subject: Re: [rtcweb] DTLS, DTLS-SRTP, and 5-tuples
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Mar 2015 13:04:09 -0000

2015-03-09 14:00 GMT+01:00 Christer Holmberg <christer.holmberg@ericsson.com>:
>> DTLS wrongly assumes a single 5-tuple. It should assume a single transport, and such a transport may be a classic 5-tuple or a ICE transport. It is a task of ICE to define what such a transport is.
>
> Yes, I agree that ICE can define such virtual transport.
>
> But, before we do that, the DTLS folks need to agree that assuming a single 5-tuple IS wrong  :)

It is as wrong as assuming that using a single **UDP** 5-tuple is safe :)


-- 
Iñaki Baz Castillo
<ibc@aliax.net>