Re: [sipcore] I-D Action: draft-ietf-sipcore-sip-token-authnz-02.txt

Christer Holmberg <christer.holmberg@ericsson.com> Tue, 09 July 2019 19:11 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: sipcore@ietfa.amsl.com
Delivered-To: sipcore@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E63F120386 for <sipcore@ietfa.amsl.com>; Tue, 9 Jul 2019 12:11:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level:
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bc3WKXA16Pit for <sipcore@ietfa.amsl.com>; Tue, 9 Jul 2019 12:11:22 -0700 (PDT)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-he1eur01on0630.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe1e::630]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 548A212004A for <sipcore@ietf.org>; Tue, 9 Jul 2019 12:11:22 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aRJvHvey70o7Eos0FBX7WZSknm6pwjwuNg9Us/IppcOwTr19KcqhEubSZKkuJyUBjVxEdnLFR9QawkMR6A9iYQ2uixBjqw+1kyM0l6N29Ao7OfZTswsLvdaujPyKyQa02/EUshasWrNUD7c0GjHUH34N4t72azlR2Har2qE3/KHSvI6tXTD45xPVG/TqREhAmu7cDJCLfvNKTpo820Jv0saW4uEg55z5Ew6HUZFXFIVbe8jJ+ujvD5UbW+dYAmY5s9WzMy1VxZ+tno9CPVhw/o/sAbL6gAb1MOnF6qAqTc7Li0kuPDQhgEPzd1yA67oW9EpVr8xnEWhsHMyooGMvBQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0APNWAErfOYuDCYjKTOj1UhQwC2B91g53lIVVmUUbT8=; b=aG04F67WEh8JmH7IC6RCMEo11ae+ymhZ7JECdIgO7cbkmR4/5Xos8fHbLPpvYvcEfueUQ5by66MAuP37mWCmsa8l4ZWSFLrbHRgZ4dJln+h2otXpLD3BSZzn21cK9PVkYDDL8EE81DIs/LXkIJXDIuMGHguDLTog0b08iUAAmcwEnQSvgFC1K/TKa38O9sCRKtP4pnuT8wX29SQBrt0H8tVrRsphwTjoGfuMN8ZHmt73kLakRd2bsUcFdu2YiyHgu1usK4dZru9AMwwHeRM2ufGzzO5ISJlpzXvnRGw25Cg1m0j3PmaXKVhu4pw05PbsXcIxvVvMQlFSvDffckQffg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=ericsson.com;dmarc=pass action=none header.from=ericsson.com;dkim=pass header.d=ericsson.com;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0APNWAErfOYuDCYjKTOj1UhQwC2B91g53lIVVmUUbT8=; b=Zm4uu97813xIS47eWxZyWoiKZy0YhDkp9lDmraXYW6ut8a4dieICvK9IWhHxsbU3CUPYZaPvJWsolupZD0twTyk4XgAGyTzzDtI/ExBnm6erkDl8T40JsZ0Cjkl5jPqg4UafyW6yb/e8I8uxVcqWjGKKPjdDBWFPB3dCHoR7jsU=
Received: from HE1PR07MB3161.eurprd07.prod.outlook.com (10.170.245.23) by HE1PR07MB3481.eurprd07.prod.outlook.com (10.170.247.152) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2073.9; Tue, 9 Jul 2019 19:11:19 +0000
Received: from HE1PR07MB3161.eurprd07.prod.outlook.com ([fe80::5050:a3a9:be80:cf43]) by HE1PR07MB3161.eurprd07.prod.outlook.com ([fe80::5050:a3a9:be80:cf43%5]) with mapi id 15.20.2073.008; Tue, 9 Jul 2019 19:11:19 +0000
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Roman Shpount <roman@telurix.com>
CC: Paul Kyzivat <pkyzivat@alum.mit.edu>, "sipcore@ietf.org" <sipcore@ietf.org>
Thread-Topic: [sipcore] I-D Action: draft-ietf-sipcore-sip-token-authnz-02.txt
Thread-Index: AQHVNLWxruT/m/C2REGBvr04oIfCDqa/Al8AgAHwRACAACa0QIAAOvWAgACKbgCAAH00gIAARqSA///8CoCAAAq/0A==
Date: Tue, 09 Jul 2019 19:11:19 +0000
Message-ID: <HE1PR07MB3161612130F07C8F727A2BB693F10@HE1PR07MB3161.eurprd07.prod.outlook.com>
References: <156249821133.14592.1211919336596009446@ietfa.amsl.com> <CAGL6epLsP_UfZMAcFLsORrR05Enu-vp=jnkgUFuKSttQm8swAw@mail.gmail.com> <c8d5c42e-ab21-80e8-3189-c8592dd02d3a@alum.mit.edu> <HE1PR07MB3161C55955B2FCED2C0F6A9993F60@HE1PR07MB3161.eurprd07.prod.outlook.com> <68ed93ae-57df-6bc7-774b-47959417abda@alum.mit.edu> <HE1PR07MB3161D46B4A44FC7E789ADDB893F10@HE1PR07MB3161.eurprd07.prod.outlook.com> <4a9787e5-b5e2-bc08-0fa0-fae6bd44148d@alum.mit.edu> <527F4C39-F065-4335-A939-6D443F1801E7@ericsson.com> <CAD5OKxuK_2+JcbGvo6LNeRbCYXWXQmhKQPNUzoZvZEOupPWyjw@mail.gmail.com>
In-Reply-To: <CAD5OKxuK_2+JcbGvo6LNeRbCYXWXQmhKQPNUzoZvZEOupPWyjw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=christer.holmberg@ericsson.com;
x-originating-ip: [62.113.190.248]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d79b6d49-9bbd-4b99-a1a1-08d704a13971
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:HE1PR07MB3481;
x-ms-traffictypediagnostic: HE1PR07MB3481:
x-microsoft-antispam-prvs: <HE1PR07MB34816E8A3621043315D034AF93F10@HE1PR07MB3481.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-forefront-prvs: 0093C80C01
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(4636009)(136003)(396003)(39860400002)(346002)(376002)(366004)(199004)(189003)(102836004)(26005)(9686003)(55016002)(99286004)(186003)(86362001)(14444005)(7696005)(6506007)(66066001)(6436002)(54906003)(478600001)(71190400001)(71200400001)(316002)(4326008)(76176011)(256004)(229853002)(33656002)(25786009)(66476007)(64756008)(66556008)(73956011)(76116006)(66446008)(66946007)(14454004)(6246003)(5660300002)(6916009)(53936002)(8936002)(476003)(52536014)(2906002)(11346002)(486006)(4744005)(68736007)(7736002)(3846002)(6116002)(74316002)(305945005)(8676002)(81156014)(81166006)(446003)(44832011); DIR:OUT; SFP:1101; SCL:1; SRVR:HE1PR07MB3481; H:HE1PR07MB3161.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: ericsson.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: EURKD+u4KQABhq8eJj76knShA0cNt2+W0zferLHXGO988x/XK2bm6HLkPFepT8E8jWbsWH+kVQ9igRlgKwT4beJMNWtsKpDuwKi+AeqsPAYD0WGpRgdDZfiPGiQpZCiI3Qh2Gjg5TlxVAUNmU7K/vY8EbGEkxjlwhPyvUOXfFnPQAuSXAJ1HibWWrAFLlc4V71M6USUOXJbXVVCecoaymnND/ATQ5286zyQUOwHiZ+CgrZitJkqNdK+WI07azXfCsq/+zgFtJtNz9qEy1IfhWKfB/C8Xj5j1k5evjyZ1a9IwvVMX9jUWS4u7WfiNg7VymMySJZ2esY4k+jFPle4aS0wLLp7rlxT4GDLm+1mQa+EZy/XlU+4pEX8aY6OgXLDKSze9yGias9o+cOr4cCXTGP3dQ8FSfcZYYAsGVbxb1hU=
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d79b6d49-9bbd-4b99-a1a1-08d704a13971
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Jul 2019 19:11:19.4859 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: christer.holmberg@ericsson.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR07MB3481
Archived-At: <https://mailarchive.ietf.org/arch/msg/sipcore/bVwggwk5w6cEoszE29Jjnji4Fng>
Subject: Re: [sipcore] I-D Action: draft-ietf-sipcore-sip-token-authnz-02.txt
X-BeenThere: sipcore@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: SIP Core Working Group <sipcore.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sipcore>, <mailto:sipcore-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sipcore/>
List-Post: <mailto:sipcore@ietf.org>
List-Help: <mailto:sipcore-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sipcore>, <mailto:sipcore-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jul 2019 19:11:24 -0000

Hi,

>> As far as I know, OAuth for SIP has only been used for REGISTER requests, between the UA and the registrar. 
>> I have never heard about anyone using it for non-REGISTER authentication, and I wonder whether we even need 
>> to cover it in the draft. We could limit the scope the REGISTER requests. Then, if anyone ever needs OAuth for non-REGISTER requests, a separate draft can be written.
> 
> Really? Normally, for a secure solution, every SIP request, including requests sent by UA in dialog established from the 
> server to the registered end point must be authenticated. OAuth for REGISTRER requests only is kind of useless since it 
> does not allow UA to send any messages to the server without some additional authentication mechanism.

Not sure what you mean by "secure solution", but UAs can still use SIP Digest authentication.

What I am saying is that only use-case for SIP OAuth I am aware of is for REGISTER.

Regards,

Christer