Re: [secdir] review of draft-ietf-sipcore-reinvite-06.txt

Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com> Fri, 19 November 2010 14:07 UTC

Return-Path: <gonzalo.camarillo@ericsson.com>
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9074D3A67E9 for <secdir@core3.amsl.com>; Fri, 19 Nov 2010 06:07:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.599
X-Spam-Level:
X-Spam-Status: No, score=-106.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cdrfJg0dGTM2 for <secdir@core3.amsl.com>; Fri, 19 Nov 2010 06:07:26 -0800 (PST)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by core3.amsl.com (Postfix) with ESMTP id 0D7963A6783 for <secdir@ietf.org>; Fri, 19 Nov 2010 06:07:24 -0800 (PST)
X-AuditID: c1b4fb3d-b7c05ae0000028e7-8f-4ce684cd1eca
Received: from esessmw0256.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id CC.81.10471.DC486EC4; Fri, 19 Nov 2010 15:08:14 +0100 (CET)
Received: from [131.160.37.44] (153.88.115.8) by esessmw0256.eemea.ericsson.se (153.88.115.97) with Microsoft SMTP Server id 8.2.234.1; Fri, 19 Nov 2010 15:08:13 +0100
Message-ID: <4CE684CD.1080902@ericsson.com>
Date: Fri, 19 Nov 2010 16:08:13 +0200
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: Stephen Kent <kent@bbn.com>
References: <p06240800c8e55027a17b@[128.89.89.159]> <4CC81942.3060502@ericsson.com> <p06240801c8fbcc3b59d7@[222.128.202.177]>
In-Reply-To: <p06240801c8fbcc3b59d7@[222.128.202.177]>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
Cc: "secdir@ietf.org" <secdir@ietf.org>, "gao.yang2@zte.com.cn" <gao.yang2@zte.com.cn>, "pkyzivat@cisco.com" <pkyzivat@cisco.com>, Christer Holmberg <christer.holmberg@ericsson.com>, "tim.polk@nist.gov" <tim.polk@nist.gov>, "rjsparks@nostrum.com" <rjsparks@nostrum.com>
Subject: Re: [secdir] review of draft-ietf-sipcore-reinvite-06.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Nov 2010 14:07:28 -0000

Hi Steve,

I have just submitted a new revision of the draft that addresses all
your comments. Thanks for your review.

http://www.ietf.org/id/draft-ietf-sipcore-reinvite-07.txt

Cheers,

Gonzalo

On 07/11/2010 5:25 AM, Stephen Kent wrote:
> Gonzalo,
> 
> Sorry for my tardy reply.
> 
> I like your changes, with a minor edit at the end:
> 
> "In particular, in order not to reduce the security level for a given
> session, re-INVITEs and UPDATE requests SHOULD be secured using a
> mechanism equivalent to or stronger than the initial INVITE request that
> created the
> session. For example, if the initial INVITE request was end-to-end
> integrity protected or encrypted, subsequent re-INVITEs and UPDATE
> requests should also be so."
> 
> 
> Steve