RE: [Sip] WGLC for auth-id body

"Mary Barnes" <mbarnes@nortelnetworks.com> Fri, 13 June 2003 17:17 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA13684 for <sip-archive@odin.ietf.org>; Fri, 13 Jun 2003 13:17:18 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5DHGpq29528 for sip-archive@odin.ietf.org; Fri, 13 Jun 2003 13:16:51 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5DGA4a25752; Fri, 13 Jun 2003 12:10:04 -0400
Received: from ietf.org (lists.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5DG9Bm25721 for <sip@optimus.ietf.org>; Fri, 13 Jun 2003 12:09:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA10789 for <sip@ietf.org>; Fri, 13 Jun 2003 12:09:08 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Qr4u-0006QA-00 for sip@ietf.org; Fri, 13 Jun 2003 12:07:00 -0400
Received: from zrc2s0jx.nortelnetworks.com ([47.103.122.112]) by ietf-mx with esmtp (Exim 4.12) id 19Qr4u-0006Q7-00 for sip@ietf.org; Fri, 13 Jun 2003 12:07:00 -0400
Received: from zrc2c011.us.nortel.com (zrc2c011.us.nortel.com [47.103.120.51]) by zrc2s0jx.nortelnetworks.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id h5DG8HE26015; Fri, 13 Jun 2003 11:08:18 -0500 (CDT)
Received: by zrc2c011.us.nortel.com with Internet Mail Service (5.5.2653.19) id <MX50C9TG>; Fri, 13 Jun 2003 11:12:38 -0500
Message-ID: <870397D7C140C84DB081B88396458DAF5789D7@zrc2c000.us.nortel.com>
From: Mary Barnes <mbarnes@nortelnetworks.com>
To: "'Peterson, Jon'" <jon.peterson@neustar.biz>, 'Robert Sparks' <rsparks@dynamicsoft.com>, Rohan Mahy <rohan@cisco.com>
Cc: sip@ietf.org, 'Dean Willis' <dean.willis@softarmor.com>, Gonzalo.Camarillo@ericsson.com
Subject: RE: [Sip] WGLC for auth-id body
Date: Fri, 13 Jun 2003 11:09:38 -0500
X-Mailer: Internet Mail Service (5.5.2653.19)
Sender: sip-admin@ietf.org
Errors-To: sip-admin@ietf.org
X-BeenThere: sip@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/sip>, <mailto:sip-request@ietf.org?subject=unsubscribe>
List-Id: Session Initiation Protocol <sip.ietf.org>
List-Post: <mailto:sip@ietf.org>
List-Help: <mailto:sip-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/sip>, <mailto:sip-request@ietf.org?subject=subscribe>

There's one more nit that I noticed that doesn't appear to be mentioned by
Robert. 

In the second paragraph of section 4, the 2nd clause of the last sentence
needs rewording.  I think it should read:
   " ..., the From header
   of the INVITE would indicate the referee, whereas a separate header
   would indicate the referrer."

Regards,
Mary.

-----Original Message-----
From: Peterson, Jon [mailto:jon.peterson@neustar.biz]
Sent: Friday, June 13, 2003 2:03 AM
To: 'Robert Sparks'; Rohan Mahy
Cc: sip@ietf.org; 'Dean Willis'; Gonzalo.Camarillo@ericsson.com
Subject: RE: [Sip] WGLC for auth-id body



Thanks for these comments. A few notes below.

Jon Peterson
NeuStar, Inc.

[snip]
> I've reviewed this document (with revision of referredby
> particularly in mind) and have the following minor comments:
> 
> - It would help section 4 to more explicitly note that it
>   is discussing using AIBs to do something beyond(besides?)
>   providing integrity protection/authentication for the 
>   request it appears in.  It would also help to capture that
>   the presence of these other things don't preclude the section
>   2 use of an AIB. Perhaps this text at end of the first paragraph
>   of section 4:
> 
>      Such information might be carried in one or more supplemental
>      AIBs. The presence of these supplemental AIBs does not preclude
>      the use of AIB as specified in this document to protect the
>      message in which they appear.
> 

Yes, I do think it is important to capture the idea that there may be
multiple AIBs in a SIP message that identify different parties. The text
given above looks good to me.

> - Instead of a special case of INVITE (see the heading of section 4), I
>   think this simply a different use of an AIB. This document constrains
>   the use of AIBs for providing integrity protection of messages and
>   authenticating their sender regardless of method type. Section 4 is
>   trying to note that other AIBs might appear that do something 
>   different. Perhaps this section could be titled "Potential additional
>   uses of AIBs"?
> 

Well, although REFER-instigated INVITEs might not be a special case as such,
most would probably say that 3PCC is a special case. But still, we need a
section title that accommodates both, so I think that's fair; a better title
for this section is probably in order. I think we need something with the
sense "Use of AIBs to express the identity of someone other than the sender
of the INVITE". I'll try to figure out a way to compress that to
header-size.

> - Section 10 (Security Considerations): The first sentence needs to
>   be scoped to the section 2 use of AIBs, not all uses of AIBs with
>   message/sipfrag in them.
> 

Okay, fine.

> - Spelling Nits:
>    * Second sentence, last paragraph Page 4: 
>        s/SHOULD be added it to/SHOULD be added to/
>    * Second sentence, last paragraph, section 4, Page 6:
>        s/harder to correlated an AIB/harder to correlate an AIB/
> 

Thanks, I'll take care of all of those.

> Other than that, I believe this document is ready to go.
> 
> RjS
> 
> On Tue, 2003-05-13 at 19:39, Rohan Mahy wrote:
> > Hello Everyone,
> > 
> > I would like to begin Working Group Last Call on
> > 
> > 
> http://www.ietf.org/internet-drafts/draft-ietf-sip-authid-body-01.txt
> > 
> > WGLC will end on Friday, June 13, 2003.
> > 
> > thanks,
> > -rohan
> > 
> > _______________________________________________
> > Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
> > This list is for NEW development of the core SIP Protocol
> > Use sip-implementors@cs.columbia.edu for questions on current sip
> > Use sipping@ietf.org for new developments on the application of sip
> 
_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sipping@ietf.org for new developments on the application of sip
_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sipping@ietf.org for new developments on the application of sip