Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch

Eric Rescorla <ekr@rtfm.com> Mon, 04 March 2013 23:36 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7BB9711E80D9 for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 15:36:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.376
X-Spam-Level:
X-Spam-Status: No, score=-102.376 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, J_CHICKENPOX_56=0.6, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QoL7KY0+qa1R for <rtcweb@ietfa.amsl.com>; Mon, 4 Mar 2013 15:36:42 -0800 (PST)
Received: from mail-qe0-f49.google.com (mail-qe0-f49.google.com [209.85.128.49]) by ietfa.amsl.com (Postfix) with ESMTP id D861F11E80D7 for <rtcweb@ietf.org>; Mon, 4 Mar 2013 15:36:40 -0800 (PST)
Received: by mail-qe0-f49.google.com with SMTP id 1so4262078qec.22 for <rtcweb@ietf.org>; Mon, 04 Mar 2013 15:36:40 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:mime-version:x-originating-ip:in-reply-to:references :from:date:message-id:subject:to:cc:content-type:x-gm-message-state; bh=hn4UyfqaQzeIOZ+SjNDQPVFYFI35cCa+h16oe8m/ocs=; b=cH3lhlxSi4Z4jZ0WN8kKDM8W9/vREm3I6tQ9dKpvCl9Rhhi/9tvseJl93dcOO40s1i PZtnjv4o7eBDJgrojFvr+0rRkK5yA9qHuTAoEckXU1G3irfj500UMg8iCJclOkZ9nza+ 2vY9ZZRYi8h40KtaWamqm6Jbsz2ZwiOoKZZDPP0vwtizYKukvaP+dQX1Dck2wfRCSRLb 60mD7krrlHNhLAOLtutzXWYbtsMEwSIpsHucwwin8Q1TqLnwh42fx2IZA4Oq/IGBhjgd asaA+xMbpct1G2vRW1upuoGKtLYxjEZujIXwXoDgrxTB0QAgXb6ixiu0zGzv5OvQldm0 /msQ==
X-Received: by 10.49.106.71 with SMTP id gs7mr38298892qeb.21.1362440200204; Mon, 04 Mar 2013 15:36:40 -0800 (PST)
MIME-Version: 1.0
Received: by 10.49.27.230 with HTTP; Mon, 4 Mar 2013 15:36:00 -0800 (PST)
X-Originating-IP: [63.245.220.224]
In-Reply-To: <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com>
References: <CA+9kkMATiwiFNyq3awr-EHwnWb3+ZEsP+Omgiwdev=8swgMrAQ@mail.gmail.com> <95790319-C42C-48E2-A6FD-0E718CCF48FB@csperkins.org> <CA+9kkMAg2grbyg1g94hm3cgV8957j++t55fuQhfWj1e_ZEGXdQ@mail.gmail.com> <CAOJ7v-0n2N5LrXQZyaZcCQZqYsHUP5U3Ox_d-RTivd2sCfZqwA@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Mon, 04 Mar 2013 15:36:00 -0800
Message-ID: <CABcZeBNf6gL8V9-F5VBG7EqBunThZs0uvS7LKjn8Beg0Qn4ozw@mail.gmail.com>
To: Justin Uberti <juberti@google.com>
Content-Type: multipart/alternative; boundary="e89a8f921a1e294fb204d721d4df"
X-Gm-Message-State: ALoCoQnAMzZkOOsrMBctPZQsLujdgocaNtDBoWh3MaQDdMUQecq6Xy+9E7cIGlvE5I9I5DAgNOUf
Cc: "rtcweb@ietf.org" <rtcweb@ietf.org>, Colin Perkins <csp@csperkins.org>
Subject: Re: [rtcweb] Reminder: Working group last call for draft-ietf-rtcweb-security-arch
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Mar 2013 23:36:43 -0000

Thanks, Justin.

I have been working on something for this and hope to have some text soon.

-Ekr


On Mon, Mar 4, 2013 at 3:30 PM, Justin Uberti <juberti@google.com> wrote:

> I already sent mail to Eric on this, but one thing that needs
> consideration in this draft is the use case identified in section 4.2.7 of
> draft-ietf-rtcweb-use-cases-and-requirements-06, i.e. desktop sharing.
> Section 5.2 of the security doc covers the requirements for consent for
> camera access, but not for desktop access.
>
>
> On Mon, Mar 4, 2013 at 8:43 AM, Ted Hardie <ted.ietf@gmail.com> wrote:
>
>> Hi Colin,
>>
>> Thanks for reviewing the document.  As you note, there are open
>> issues; 5.1, for example, has this:
>>
>> "This is a  deliberate implementation complexity versus security tradeoff.
>>  [[ OPEN ISSUE::  Should we be more aggressive about this?]]"
>>
>> As far as I am aware,though, the document in each case includes a
>> proposal for the Open Issue,
>> and it is that which would be in a WG document post last-call.  But if
>> folks looked at the document
>> and answered the "open issues" within, that would certainly be very
>> welcome input.
>>
>> Were there any Open Issues or other points you wanted to comment on
>> directly?
>>
>> Ted
>>
>>
>> but there
>>
>> On Mon, Mar 4, 2013 at 4:58 AM, Colin Perkins <csp@csperkins.org> wrote:
>> > Ted,
>> >
>> > This draft has a number of places where open issues are noted (e.g., in
>> Sections 5.1 and 5.5, but there are many others). It seems premature to
>> issue a working group last call until those are resolved.
>> >
>> > Colin
>> >
>> >
>> >
>> > On 25 Feb 2013, at 23:27, Ted Hardie wrote:
>> >> This is a reminder that there is an ongoing last call for
>> >> draft-ietf-rtcweb-security-arch-06.  Please send comments, including
>> >> those of the "reviewed and no issues" ilk, by March 9th, 2012.
>> >>
>> >> regards,
>> >>
>> >> Ted Hardie
>> >>
>> >> On Thu, Feb 14, 2013 at 8:35 AM, Ted Hardie <ted.ietf@gmail.com>
>> wrote:
>> >>> This begins a working group last call for
>> >>> draft-ietf-rtcweb-security-arch.  Please send comments to the list by
>> >>> March 9, 2013.
>> >>>
>> >>> regards,
>> >>>
>> >>> Ted, Cullen, Magnus
>> >> _______________________________________________
>> >> rtcweb mailing list
>> >> rtcweb@ietf.org
>> >> https://www.ietf.org/mailman/listinfo/rtcweb
>> >
>> >
>> >
>> > --
>> > Colin Perkins
>> > http://csperkins.org/
>> >
>> >
>> >
>> _______________________________________________
>> rtcweb mailing list
>> rtcweb@ietf.org
>> https://www.ietf.org/mailman/listinfo/rtcweb
>>
>
>
> _______________________________________________
> rtcweb mailing list
> rtcweb@ietf.org
> https://www.ietf.org/mailman/listinfo/rtcweb
>
>