Re: [sipcore] Applicability of privacy "header"
Jörgen Axell <jorgen.axell@ericsson.com> Wed, 21 June 2017 07:24 UTC
Return-Path: <jorgen.axell@ericsson.com>
X-Original-To: sipcore@ietfa.amsl.com
Delivered-To: sipcore@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3D06D13169A for <sipcore@ietfa.amsl.com>; Wed, 21 Jun 2017 00:24:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.219
X-Spam-Level:
X-Spam-Status: No, score=-4.219 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OI5Kk9Cvyzv7 for <sipcore@ietfa.amsl.com>; Wed, 21 Jun 2017 00:24:28 -0700 (PDT)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 48030131692 for <sipcore@ietf.org>; Wed, 21 Jun 2017 00:24:28 -0700 (PDT)
X-AuditID: c1b4fb25-545149a0000046b1-29-594a1f29e734
Received: from ESESSHC017.ericsson.se (Unknown_Domain [153.88.183.69]) by sesbmg23.ericsson.net (Symantec Mail Security) with SMTP id FF.80.18097.92F1A495; Wed, 21 Jun 2017 09:24:26 +0200 (CEST)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (153.88.183.145) by oa.msg.ericsson.com (153.88.183.69) with Microsoft SMTP Server (TLS) id 14.3.339.0; Wed, 21 Jun 2017 09:24:25 +0200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.onmicrosoft.com; s=selector1-ericsson-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=qDm7GjHVpv/S8Xm7qENLMvfgm7uAecOD0oQWsQU+OjU=; b=h40QXUDwnOLR+T2lXMbXlO+N36pyum1Gk9ddfxsxb37ffvnXiwzl23nV4Lafk77OkzMq9yTdGcJq8dNoNiSsBJ9xEaDsKrLcx2MM10BIuLQMT65kj/psBuUQB5W8cJaWv7UHOaQZkP73PPJtptY8/dEMUbWJmehZWUvZq/t722c=
Received: from DB5PR07MB0949.eurprd07.prod.outlook.com (10.161.200.144) by DB5PR07MB1128.eurprd07.prod.outlook.com (10.163.103.158) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1199.6; Wed, 21 Jun 2017 07:24:24 +0000
Received: from DB5PR07MB0949.eurprd07.prod.outlook.com ([fe80::786b:3958:f904:6158]) by DB5PR07MB0949.eurprd07.prod.outlook.com ([fe80::786b:3958:f904:6158%15]) with mapi id 15.01.1199.007; Wed, 21 Jun 2017 07:24:24 +0000
From: Jörgen Axell <jorgen.axell@ericsson.com>
To: "Drage, Keith (Nokia - GB)" <keith.drage@nokia.com>, Brett Tate <brett@broadsoft.com>, sipcore <sipcore@ietf.org>
Thread-Topic: [sipcore] Applicability of privacy "header"
Thread-Index: AdLgVuV3cRKOBgDATtSoJsORYTazzgA2FPyAAi0y/WAAHldAUA==
Date: Wed, 21 Jun 2017 07:24:24 +0000
Message-ID: <DB5PR07MB0949E00E6A44E088C957EBA9E0DA0@DB5PR07MB0949.eurprd07.prod.outlook.com>
References: <DB5PR07MB094943B7AED6B88CAD36132DE0C90@DB5PR07MB0949.eurprd07.prod.outlook.com> <c06ca11ad845a450da5b77790af44c23@mail.gmail.com> <DB5PR07MB1480A3838252607E5B04974AF7DA0@DB5PR07MB1480.eurprd07.prod.outlook.com>
In-Reply-To: <DB5PR07MB1480A3838252607E5B04974AF7DA0@DB5PR07MB1480.eurprd07.prod.outlook.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: nokia.com; dkim=none (message not signed) header.d=none;nokia.com; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [192.176.1.92]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DB5PR07MB1128; 7:Fh58s+FiG6ZEnB+eu15pquSO9TOeuWWDlweFFaAgjDKqskNnKI4xXeTvX+0f6YvgmlLypSGw4EKixqLveot2NiSN9qP30L44l+ntMYSGTH1Y+L0B8OU/r8321LXQfbMbqMZ+YDS+sXONIuZ12qJ5lREX9Z32LXUffFKMpzlkF3jusi9REhqBX5BLVWWOYgnEwNzOLf/aicuROYyG4qITbW+HIrXoFLpGyUEfMIPF5lBWrqaqZABmT2FaOv1trc8SjshFvOiVxdnD/kLO5yGYgzPQgsnt5WrO6kGNa7XH1hMypRNq9jQf40/Qokv+d9V3tpeH741k7aIn4NW/HJtxR3VMSeqPcLK4Tf8eFgfV/vZcy1pPaQYYtqpXkbObVdz3d7NlDBQU7Ql5pXNF9X2ya1oXaYOVPoPNqVCiuqdWr6mONKbPR4okSN8C7FM/gkis4y/rxo+Nz65PHxH7M3FUpBuC7KGMcXmrTx0kZdZmhmaG/7vZ5p+ZjmqfE/QCUXVO4HuqbvxqJgtykZqFRIqwn4W5NeAVdj+HE/NCtpRJNI4Gk8DJjzegv758bzK13Vzbwqu2ZFlSrlFCDRQVTOVt6h9e4vTATlFvAQQwGUIhKMBzWPnbtRbeWy126VCLsTYqiDIMt5QXMEAkZM6ekLop0McDKJlPSiyKY13L9YiLrZNJhm1fMxFurg4xIsZ0193Lqgna6LEVyteXuAw6dwsWzLrkNX5qQ6jl1FNPBNqa8DVMCGipvR6XGuOApheMqTogmOkNCi9HV5uENQuQQnKVoT33VCCaHgiIsyusPQj1UpE=
x-ms-office365-filtering-correlation-id: c53403b9-8949-41a2-c222-08d4b8768b08
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254075)(201703131423075)(201703031133081); SRVR:DB5PR07MB1128;
x-ms-traffictypediagnostic: DB5PR07MB1128:
x-microsoft-antispam-prvs: <DB5PR07MB11283E2B72531B173149173DE0DA0@DB5PR07MB1128.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(37575265505322)(10436049006162)(202460600054446)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(8121501046)(5005006)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(3002001)(6041248)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123555025)(20161123564025)(20161123560025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DB5PR07MB1128; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DB5PR07MB1128;
x-forefront-prvs: 0345CFD558
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(39450400003)(39840400002)(39850400002)(39860400002)(39410400002)(39400400002)(377454003)(43544003)(38730400002)(2900100001)(3846002)(102836003)(790700001)(6116002)(7906003)(53546010)(14454004)(229853002)(53936002)(54896002)(236005)(6306002)(66066001)(33656002)(85202003)(54356999)(76176999)(50986999)(99286003)(55016002)(9686003)(7736002)(6436002)(606005)(3660700001)(3280700002)(8676002)(85182001)(5660300001)(2950100002)(6506006)(25786009)(478600001)(86362001)(81166006)(74316002)(8936002)(7696004)(189998001)(5250100002); DIR:OUT; SFP:1101; SCL:1; SRVR:DB5PR07MB1128; H:DB5PR07MB0949.eurprd07.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DB5PR07MB0949E00E6A44E088C957EBA9E0DA0DB5PR07MB0949eurp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Jun 2017 07:24:24.2310 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB5PR07MB1128
X-OriginatorOrg: ericsson.com
X-Brightmail-Tracker: H4sIAAAAAAAAA02SfUhTURjGO7v3btfR6LS0vczEHA0/MteHf8yKSCkQRbSMUFFsuetHOpVN LRXCkhLnR2ZablpTGQZqZCoZkoFDUCM/MilZaJoTkYyBWc0Ua9vV8L/feZ7nvO95Xw5NCLsp MZ2WmcOoMxUZEi6f1MX0nD/i5xkWe7TFRMmLDZtI3tE9SMp/2jq5Z4lQ2+cLoUbjGid02jzB iSLi+KeVTEZaHqOWnbnCT/1VNcPJNg+jG/XLVl4R6hhAWuRCAw4Ey9JdSov4tBAPIPhr7nMa QjyEoHuq0GGQuIIAY98TDpuq40CFVUuyh3kEthEb4bjCxSHQUjRKOdgVXwdt04KT92E5NM63 c1k9CIrrKwmWQ6Dk/aIzQ2IplNzvsWdoWoDj4e2M7H/9kVktz5FxwQnQPPrUyQh7wOqtNmcd AovAbDFw2HkwGF+PESy7wdL8pnM2hCsQ1G6UkaxxEDYmvnJZ9oAJQxlyhADPcqG4vXprMxFQ 0/mbYvkmrCwvko7XAfaD0heXWDkd6h/Okds8Nqkl2DomCtbH720ZB+Dl7XKKNboo6B1/RLJr EcP0ZCmqQr76HVOwnAVtfVYnC/BeGNZZSL29N4F94XmvjI14QU3ZHI9lH7jT8Ji3U29EvFbk pmE0V1Upx08EMOq0JI0mKzMgk8npRPa/1N+9Ln2FPiwHmxCmkWS3IFcUFiukFHmafJUJAU1I XAWRArskUCryCxh1VqI6N4PRmJA7TUpEguA34zFCnKLIYdIZJptRb7sc2kVchKrdmwpNdVrv tPAiEMR/WrBE9Aeao7x1h0/xIj0bxkT+q1+G9szBIffqruQoqbK8IFH1IFksXWhtJqV0tDI8 /5ztz5TsR/xgmarD66SsVkuNMhJ9wsWBtTgf5l2f7ppLnnXXs5bv2OCxIP6WmPRx/4r/+kyQ pFLvo4xmpi5LSE2q4pgfodYo/gHZMoSERwMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/sipcore/5FpPs9AgsPxHF2Sq7R8ZvOa48TA>
Subject: Re: [sipcore] Applicability of privacy "header"
X-BeenThere: sipcore@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: SIP Core Working Group <sipcore.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sipcore>, <mailto:sipcore-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sipcore/>
List-Post: <mailto:sipcore@ietf.org>
List-Help: <mailto:sipcore-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sipcore>, <mailto:sipcore-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2017 07:24:32 -0000
Multiple privacy values are normal. The question is how much and if they overlap. Of course an entity providing privacy acts on the types it understands. P-Asserted-ID is providing information about the user, but it is not added by the UE, it is added by the network. So the argument that the P-Asserted-ID is out of scope of header privacy in RFC3323 is that the RFC 3323 defined privacy service only applies to "privacy functions for SIP messages that cannot be provided by user agents themselves" and since RFC 3325 gives the UE a tool (privacy value "id") to provide privacy then P-Asserted-ID is out of scope for the privacy service defined in RFC 3323.
This is similar to why header privacy does not affect the From header field ("user" privacy is used for this). The UE can take care of this itself by setting the header to an anonymous URI.
Or do you think there is a fundamental difference between including a Privacy "id" from setting the From header field to anonymous@anonymous.invalid?
Jörgen
From: sipcore [mailto:sipcore-bounces@ietf.org] On Behalf Of Drage, Keith (Nokia - GB)
Sent: 21 June 2017 02:13
To: Brett Tate <brett@broadsoft.com>; sipcore <sipcore@ietf.org>; Jörgen Axell <jorgen.axell@ericsson.com>
Subject: Re: [sipcore] Applicability of privacy "header"
I have to say that I think the opposite is actually the case.
The various different privacy types may be enacted by multiple different entities within the network, and each of those entities might not know which other entities in the SIP path exist. Additionally the invoking UE may want to cover all bases by including as many protections as possible. Therefore it is certainly reasonable to me that multiple privacy types can appear in the same Privacy header field.
Any entity providing privacy should therefore fulfil the semantics of the privacy type it sees, understands, and provides capability for. Given that the P-Asserted-ID clearly is a header field providing information about the user, the it should be suppressed if header privacy is enacted.
I agree it could be argued that such a header field should not be in a message where header privacy is requested, but that should not stop it being removed if it is present.
Regards
Keith
From: sipcore [mailto:sipcore-bounces@ietf.org] On Behalf Of Brett Tate
Sent: 09 June 2017 15:47
To: sipcore <sipcore@ietf.org<mailto:sipcore@ietf.org>>; Jörgen Axell <jorgen.axell@ericsson.com<mailto:jorgen.axell@ericsson.com>>
Subject: Re: [sipcore] Applicability of privacy "header"
Hi,
The following snippet from RFC 3325 section 9.3 seems applicable: “Note that a user requesting multiple types of privacy MUST include all of the requested privacy types in its Privacy header field value.”
Concerning "header", RFC 3323 indicates “server SHOULD NOT add any headers to the message that reveal any identity”. However, my recollection is that it doesn’t prevent intermediaries from adding PAI with/without intermediary also adding privacy "id".
Thus, your interpretation sounds correct.
From: sipcore [mailto:sipcore-bounces@ietf.org<mailto:sipcore-bounces@ietf.org>] On Behalf Of Jörgen Axell
Sent: Thursday, June 08, 2017 9:30 AM
To: 'sipcore'
Subject: [sipcore] Applicability of privacy "header"
I have been involved in recent discussions on whether Privacy: "header" applies to P-Asserted-Identity, or rather whether the original meaning of RFC 3323 was that it applies to PAI. The uncertainty introduced in RFC 3323 is imported by 3GPP by explicit references.
The reason this is unclear is that RFC 3323 section 5 states that the document defines the logical role of "privacy service" and states the applicability as: "The function of a privacy service is to supply privacy functions for SIP messages that cannot be provided by user agents themselves." So in my mind the question is whether the inclusion of Privacy: "id" by a UA as specified in RFC 3325 fulfills the "provided by user agents themselves."
It makes logical sense to not cover PAI with "header" as there is a separate privacy value for this.
Anyone having a comment or knows the original intent?
Regards,
Jörgen
Dr. JÖRGEN AXELL
Senior specialist
Business Unit Cloud and IP
Ericsson
Grönlandsgatan 31
164 80 Stockholm, Sweden
Phone +46 10 719 4450
Mobile +46 70 519 4450
Jorgen.Axell@ericsson.com<mailto:Jorgen.Axell@ericsson.com>
www.ericsson.com<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ericsson.com&d=DwQFAw&c=uiYkEnhlQB0H-gDwErXr4Q&r=8Yr-1qTsPmhitR1Vv92TJ3hY6pQbjzLOi7kQZYxxXJY&m=lop9AQtw4m7WqeALFbxQ2YwvFQ3_iQZPMYOg8m1OuFQ&s=iRz8s-E_kjz4ZfrN3DHn2THWV8TgWZu5A-gqP_qGYhM&e=>
Legal entity: Ericsson AB, registered office in Kista. This Communication is Confidential. We only send and receive email on the basis of the terms set out at www.ericsson.com/email_disclaimer<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ericsson.com_email-5Fdisclaimer&d=DwMFAw&c=uiYkEnhlQB0H-gDwErXr4Q&r=8Yr-1qTsPmhitR1Vv92TJ3hY6pQbjzLOi7kQZYxxXJY&m=lop9AQtw4m7WqeALFbxQ2YwvFQ3_iQZPMYOg8m1OuFQ&s=IBineJYihvvkPriK4cufXct5XCb1f1i2SkKTGmIbKwY&e=>
- [sipcore] Applicability of privacy "header" Jörgen Axell
- Re: [sipcore] Applicability of privacy "header" Brett Tate
- Re: [sipcore] Applicability of privacy "header" Drage, Keith (Nokia - GB)
- Re: [sipcore] Applicability of privacy "header" Jörgen Axell
- Re: [sipcore] Applicability of privacy "header" Drage, Keith (Nokia - GB)
- Re: [sipcore] Applicability of privacy "header" Jörgen Axell