Re: [secdir] secdir review of draft-ietf-behave-turn-uri-03.txt

Magnus Westerlund <magnus.westerlund@ericsson.com> Wed, 21 October 2009 11:08 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: secdir@core3.amsl.com
Delivered-To: secdir@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C15713A69F8; Wed, 21 Oct 2009 04:08:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.239
X-Spam-Level:
X-Spam-Status: No, score=-6.239 tagged_above=-999 required=5 tests=[AWL=0.010, BAYES_00=-2.599, HELO_EQ_SE=0.35, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wsVllAdoKIXw; Wed, 21 Oct 2009 04:08:33 -0700 (PDT)
Received: from mailgw5.ericsson.se (mailgw5.ericsson.se [193.180.251.36]) by core3.amsl.com (Postfix) with ESMTP id 6A6AA3A697D; Wed, 21 Oct 2009 04:08:32 -0700 (PDT)
X-AuditID: c1b4fb24-b7bd7ae000002270-08-4adeebb79809
Received: from esealmw129.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw5.ericsson.se (Symantec Mail Security) with SMTP id 62.15.08816.7BBEEDA4; Wed, 21 Oct 2009 13:08:39 +0200 (CEST)
Received: from esealmw127.eemea.ericsson.se ([153.88.254.171]) by esealmw129.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Wed, 21 Oct 2009 13:08:29 +0200
Received: from [147.214.183.250] ([147.214.183.250]) by esealmw127.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.3959); Wed, 21 Oct 2009 13:08:28 +0200
Message-ID: <4ADEEBAC.9050405@ericsson.com>
Date: Wed, 21 Oct 2009 13:08:28 +0200
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
User-Agent: Thunderbird 2.0.0.23 (Windows/20090812)
MIME-Version: 1.0
To: Magnus Westerlund <magnus.westerlund@ericsson.com>, Marc Petit-Huguenin <petithug@acm.org>, "iesg@ietf.org" <iesg@ietf.org>, "secdir@ietf.org" <secdir@ietf.org>
References: <20091019094603.GB4708@elstar.local> <4ADDFA8A.40902@acm.org> <20091021095157.GC3177@elstar.local> <4ADEDBE2.2090704@ericsson.com> <20091021102752.GA4104@elstar.local>
In-Reply-To: <20091021102752.GA4104@elstar.local>
X-Enigmail-Version: 0.96.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
X-OriginalArrivalTime: 21 Oct 2009 11:08:28.0582 (UTC) FILETIME=[D143EC60:01CA523E]
X-Brightmail-Tracker: AAAAAA==
Subject: Re: [secdir] secdir review of draft-ietf-behave-turn-uri-03.txt
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Oct 2009 11:08:33 -0000

Juergen Schoenwaelder skrev:
> On Wed, Oct 21, 2009 at 12:01:06PM +0200, Magnus Westerlund wrote:
>  
>> I do understand your confusion. RFC 5389 is STUN. TURN is an extension
>> of STUN, and TURN mandates authentication. The default to use mechanism
>> however, is defined in STUN, thus the reference to RFC 5389.
> 
> Thanks, now I understand this better. So does this wording describe
> the situation correctly:
> 
>    This is achieved for "turn" URIs by the Long-Term Credential
>    Mechanism defined in [RFC5389], which is mandatory for TURN
>    [RFCxxx]. For a "turns" URI, the usage of TLS addresses the
>    requirement."
> 
> Having both references would have helped me to understand the
> situation better (showing my ignorance of TURN ;-).

Yes, I think that part is good.

I would note that TLS may not be sufficient for reaching the
authentication goal. Only that is has the capability to reach them. But
also for TLS you can use the Long-Term Credential mechanism to
authenticate the user of a TURN server.

Cheers

Magnus Westerlund

IETF Transport Area Director
----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM
----------------------------------------------------------------------
Ericsson AB                | Phone  +46 10 7148287
Färögatan 6                | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden| mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------