Re: [sipcore] Security Issue

Paul Kyzivat <pkyzivat@cisco.com> Wed, 08 December 2010 15:50 UTC

Return-Path: <pkyzivat@cisco.com>
X-Original-To: sipcore@core3.amsl.com
Delivered-To: sipcore@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8BA1D3A6803 for <sipcore@core3.amsl.com>; Wed, 8 Dec 2010 07:50:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.51
X-Spam-Level:
X-Spam-Status: No, score=-110.51 tagged_above=-999 required=5 tests=[AWL=0.089, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3cSICz9068Jy for <sipcore@core3.amsl.com>; Wed, 8 Dec 2010 07:50:22 -0800 (PST)
Received: from rtp-iport-2.cisco.com (rtp-iport-2.cisco.com [64.102.122.149]) by core3.amsl.com (Postfix) with ESMTP id 9711E3A695C for <sipcore@ietf.org>; Wed, 8 Dec 2010 07:50:22 -0800 (PST)
Authentication-Results: rtp-iport-2.cisco.com; dkim=neutral (message not signed) header.i=none
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AlUFAOY4/0xAZnwN/2dsb2JhbACVN44keKRim0GFSQSEYoYPgxQ
X-IronPort-AV: E=Sophos;i="4.59,316,1288569600"; d="scan'208";a="190647664"
Received: from rtp-core-2.cisco.com ([64.102.124.13]) by rtp-iport-2.cisco.com with ESMTP; 08 Dec 2010 15:51:50 +0000
Received: from [161.44.174.115] (dhcp-161-44-174-115.cisco.com [161.44.174.115]) by rtp-core-2.cisco.com (8.13.8/8.14.3) with ESMTP id oB8Fpn6g001109 for <sipcore@ietf.org>; Wed, 8 Dec 2010 15:51:50 GMT
Message-ID: <4CFFA995.8000408@cisco.com>
Date: Wed, 08 Dec 2010 10:51:49 -0500
From: Paul Kyzivat <pkyzivat@cisco.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.12) Gecko/20101027 Thunderbird/3.1.6
MIME-Version: 1.0
To: sipcore@ietf.org
References: <AANLkTinEk6VpQYKoNHPhowv69-7V1KwDgC1o9sbQjssU@mail.gmail.com>
In-Reply-To: <AANLkTinEk6VpQYKoNHPhowv69-7V1KwDgC1o9sbQjssU@mail.gmail.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: Re: [sipcore] Security Issue
X-BeenThere: sipcore@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: SIP Core Working Group <sipcore.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sipcore>, <mailto:sipcore-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sipcore>
List-Post: <mailto:sipcore@ietf.org>
List-Help: <mailto:sipcore-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sipcore>, <mailto:sipcore-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 08 Dec 2010 15:50:26 -0000

IIUC you posted earier to sip-implementors, not sipcore.

If your issues are simply implementation concerns, it would be best to 
continue your discussion there.

If you think your issues are deficiencies or errors in the specs, then 
this is probably the right place. If so, please repost here the details 
you are concerned with.

(I seem to recall some message(s) on the subjects you mention, but not 
any details. I get too much mail to monitor and respond more than 
sporadically and opportunistically to sip-implementors.)

	Thanks,
	Paul

On 12/8/2010 3:25 AM, Samir Srivastava wrote:
> Hi,
>    I am getting active after a long pause. Trying to figure out the details.
>    I posted earlier on the SIP Implementors regarding the
>    1)  security for other URI such as IM, PRES, TEL
>    2)  feature control such as presence information sent over the secure
> channel is distributed over the unsecure channel.
>    3)  Alongwith other issues, which I was pointing earlier on the list.
>    Does anybody has answer to 1) and 2) or not or what is the plan?
>    Paul, Dale other folks active here and active there too. I was
> expecting it might have resolved either way to know the result.
> Thx
> Samir Srivastava
>
>
>
> _______________________________________________
> sipcore mailing list
> sipcore@ietf.org
> https://www.ietf.org/mailman/listinfo/sipcore