Re: [secdir] review of draft-ietf-sipcore-reinvite-06.txt

Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com> Mon, 08 November 2010 06:01 UTC

Return-Path: <gonzalo.camarillo@ericsson.com>
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 991C53A69C0 for <secdir@core3.amsl.com>; Sun, 7 Nov 2010 22:01:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.511
X-Spam-Level:
X-Spam-Status: No, score=-106.511 tagged_above=-999 required=5 tests=[AWL=0.088, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nkUMUIdq2YRt for <secdir@core3.amsl.com>; Sun, 7 Nov 2010 22:00:59 -0800 (PST)
Received: from mailgw9.se.ericsson.net (mailgw9.se.ericsson.net [193.180.251.57]) by core3.amsl.com (Postfix) with ESMTP id 7781C3A69B3 for <secdir@ietf.org>; Sun, 7 Nov 2010 22:00:59 -0800 (PST)
X-AuditID: c1b4fb39-b7b54ae000003464-e1-4cd7922f305b
Received: from esealmw129.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw9.se.ericsson.net (Symantec Mail Security) with SMTP id 80.65.13412.F2297DC4; Mon, 8 Nov 2010 07:01:19 +0100 (CET)
Received: from esealmw127.eemea.ericsson.se ([153.88.254.171]) by esealmw129.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Mon, 8 Nov 2010 07:01:18 +0100
Received: from [131.160.126.193] ([131.160.126.193]) by esealmw127.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Mon, 8 Nov 2010 07:01:18 +0100
Message-ID: <4CD79229.8040400@ericsson.com>
Date: Mon, 08 Nov 2010 14:01:13 +0800
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: Stephen Kent <kent@bbn.com>
References: <p06240800c8e55027a17b@[128.89.89.159]> <4CC81942.3060502@ericsson.com> <p06240801c8fbcc3b59d7@[222.128.202.177]>
In-Reply-To: <p06240801c8fbcc3b59d7@[222.128.202.177]>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 08 Nov 2010 06:01:18.0597 (UTC) FILETIME=[5C59A350:01CB7F0A]
X-Brightmail-Tracker: AAAAAA==
Cc: "secdir@ietf.org" <secdir@ietf.org>, "gao.yang2@zte.com.cn" <gao.yang2@zte.com.cn>, "pkyzivat@cisco.com" <pkyzivat@cisco.com>, Christer Holmberg <christer.holmberg@ericsson.com>, "tim.polk@nist.gov" <tim.polk@nist.gov>, "rjsparks@nostrum.com" <rjsparks@nostrum.com>
Subject: Re: [secdir] review of draft-ietf-sipcore-reinvite-06.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Nov 2010 06:01:00 -0000

Hi Stephen,

I agree with your proposed edit. I will revise the draft accordingly.

Thanks,

Gonzalo

On 07/11/2010 11:25 AM, Stephen Kent wrote:
> Gonzalo,
> 
> Sorry for my tardy reply.
> 
> I like your changes, with a minor edit at the end:
> 
> "In particular, in order not to reduce the security level for a given
> session, re-INVITEs and UPDATE requests SHOULD be secured using a
> mechanism equivalent to or stronger than the initial INVITE request that
> created the
> session. For example, if the initial INVITE request was end-to-end
> integrity protected or encrypted, subsequent re-INVITEs and UPDATE
> requests should also be so."
> 
> 
> Steve