Re: [sipcore] Draft new version: draft-ietf-sipcore-sip-token-authnz-14 (was: Benjamin Kaduk's Discuss on draft-ietf-sipcore-sip-token-authnz-13)

Christer Holmberg <christer.holmberg@ericsson.com> Sat, 02 May 2020 13:46 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: sipcore@ietfa.amsl.com
Delivered-To: sipcore@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 90D5A3A1207 for <sipcore@ietfa.amsl.com>; Sat, 2 May 2020 06:46:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.921
X-Spam-Level:
X-Spam-Status: No, score=-2.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.82, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id flVvdMVQdqf3 for <sipcore@ietfa.amsl.com>; Sat, 2 May 2020 06:46:51 -0700 (PDT)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-eopbgr130055.outbound.protection.outlook.com [40.107.13.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 04FD53A1205 for <sipcore@ietf.org>; Sat, 2 May 2020 06:46:50 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=QssZairv9mDpRZaKhKZOd7ZVBVEVU5l4qxRXCa1hgBhHRWCNvNDf6OEOdJAsIK5+FX8hDHGjAqGEfJu4E69aVRvD7Ca1z8Zyad3l0oP62cjECqJykFRTR2f5WHbqoqprPpKxX2W4AdaYt3fPWbv0jmIMBzqnuu9ZlI5wa97dZZbLOmPT5L1lOm/HFARYe+E/byZR3ptmBfMCG+7qYevRD0EUH/Xw17P6mQ0D+GSZDepzCzvN2EQUu9Mx/KG9wbxyaVQGzIOnQxMvBD4qSj0yn/NhTxIKtu23KCf0BJWZFdbG01oKVNSwW/HyN46tDZPHVArlDgcyu/e1rDzszco6HA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NtR3gQG2a5p3NPUHb5hSs87b9seK+sT3ZJ8S1zqQlX8=; b=TpEbDRdllZ+7XYFQmsx3Yx4x8TfV5lS4WdDwBlHFTYREN3j7cRLbvvBn7FfDqXNAQVuRrFwTZQTuQdO2T74mlbB8MxZq6XOFMTweWtsUCtv/49gr8LO/7SDjszV12J00dg13ZwCzaBPJbRnSRcYlLjzLjaS+5RsKj5X6J1Dyvk04zsBI7Xsdh/WSCYo+h3QyyHooANDu8cAouPFoA5o97c9ug3e+qvlayggMsa+oETP1TbtEuu3yX9rsi4X5nbO7pw+4a0KHNqa8z2j/qZujQzX7IEvGZuwenyqAwIAsi4lnxHEHmZjY+rrHvAGeCpZrfXaPT1wWVqXwg6NMIq6gxQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=NtR3gQG2a5p3NPUHb5hSs87b9seK+sT3ZJ8S1zqQlX8=; b=jwSbwoIYnrgrAMG4C4F0cF3nTdd4450IKMkjus2DNs/mgrhM5eSNCTMPxCVPK7je12rYoePDKbJT5gs8iC+og8Mn+smSyJPuKh90lOka9+mSDnXlWlBHT1MR//8F6AjMokAo0Dmg02YeyHnjtxNeqIa7jFGgUzBGrdQXoLXs3ww=
Received: from AM7PR07MB7012.eurprd07.prod.outlook.com (2603:10a6:20b:1bc::19) by AM7PR07MB6531.eurprd07.prod.outlook.com (2603:10a6:20b:1ab::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2979.14; Sat, 2 May 2020 13:46:48 +0000
Received: from AM7PR07MB7012.eurprd07.prod.outlook.com ([fe80::4c:e502:13cf:87a8]) by AM7PR07MB7012.eurprd07.prod.outlook.com ([fe80::4c:e502:13cf:87a8%4]) with mapi id 15.20.2979.022; Sat, 2 May 2020 13:46:48 +0000
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: Paul Kyzivat <pkyzivat@alum.mit.edu>, "sipcore@ietf.org" <sipcore@ietf.org>
Thread-Topic: [sipcore] Draft new version: draft-ietf-sipcore-sip-token-authnz-14 (was: Benjamin Kaduk's Discuss on draft-ietf-sipcore-sip-token-authnz-13)
Thread-Index: AQHWHugd3GnIoSQ2kUWAEgk7QKROLaiUzoeAgAA2MwA=
Date: Sat, 02 May 2020 13:46:48 +0000
Message-ID: <2E6C8481-0A60-4409-90BC-5717A5353AAB@ericsson.com>
References: <27C3E7FD-D540-4846-9805-08358F39713A@ericsson.com> <b7c1300a-7e1e-8f9b-88fa-83fadd5cd406@alum.mit.edu>
In-Reply-To: <b7c1300a-7e1e-8f9b-88fa-83fadd5cd406@alum.mit.edu>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.1e.0.191013
authentication-results: alum.mit.edu; dkim=none (message not signed) header.d=none;alum.mit.edu; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [188.127.223.154]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 5f70f511-a8a4-48c9-a6de-08d7ee9f42e7
x-ms-traffictypediagnostic: AM7PR07MB6531:
x-microsoft-antispam-prvs: <AM7PR07MB65311979A1DB8F4B612B5E7F93A80@AM7PR07MB6531.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:5797;
x-forefront-prvs: 039178EF4A
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 5/7wRJneQDmmAeS9p2o0/1rIm5J8D2vpBUWkjEMIe76iyfQ/ubyRlHLgde4dBmkFQNChGuK1Kr0DTG9fErwpZUEOHfKZsMB1Nbes0zamIQjQQs09AR4vAmcPkQix3ZEgpf534QxzpgBdy9eLcXa0lQ+CE9FIwGyZ04Vz9A2M/d2nopkYmtUc5CkKsVelCrytwVKvOmNsaMY78z0g5MgY3ySqeIItBHIVphz0OhQMprxOnnwKByIK2cTBpEVGjZ+61xMvmTJssk0VplTvTgc8m059425VThMD0oqkZoOHqX/Cgf60KkVN6fuGNdJyaMblhO5u4OwLfHBS8nuCJGL2KusIkwDNKfRQ8WeWVHj0vvs3/rd9Vo+zJh7by0k53FSvf35MELnLQE0Bt9b8F4wdOF6DT5Az4sDdb35LdMsmiaCmdPkJHcwxqKqtdOtO1ropnYT+RPo6FjL6/nepbbwC1sToqNR6pzW2QWs6k71LPpojJe4xGOfDVJ09scg9y80AvowoOnMhDmByj0Lb7umALw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AM7PR07MB7012.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(136003)(366004)(396003)(39860400002)(346002)(376002)(110136005)(186003)(6512007)(53546011)(6506007)(316002)(26005)(6486002)(36756003)(33656002)(5660300002)(2906002)(66446008)(64756008)(44832011)(2616005)(66476007)(478600001)(86362001)(966005)(8676002)(8936002)(66946007)(76116006)(71200400001)(91956017)(66556008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: ChE4pKooqK0JwQneHfQ9zy1umwhi+p5qHhNMkFK70OhbAIfJr2w5DWy5uj8psOkr4NHb0x06GKTl5uumC0htBZTaNGjiofk407Asz2NSpKMOhdw6BfhdV6L1n5OiNdqXUOihy2VmJ33nu3jciflYBZBlEtDx6y68d/bFbhAcFKblzW2ImvB+C2OyFE9jGvjhwbeSB+Df6s98m/ZrpsFTaD3F438pq3rpV62LYYC+3DRZJXV9M+iUDNy3Q7daE6VHqbn3XP5erCyV/F/leEWS4img6lH6V5I5UZcU9416Uo1jT0h+s57iupJaXbDKv+XWDGWcwaSq3CtStwMRzc7edfwJ4XAvHW8rzdwo4hdJibKvTPE639z0S5tVNRfA3bSjHjke3PGC+RuQMsXok1Zc2iEjeZwZs7xBPnpagHavJCM5Cw0T3qIvVxZVhrwhnRzupoHKouZRKKwMecaDjjxninDikh2e4Dxc8dJIKm8Lsbz85oSG/gt7pSmnQkacfrB1rNwllKvaC2XkISps877tjn6J9saNzA58L71hKsKst7rRNobYvqBUbvvk0NvFaEvbh4YPnfOKXUSr3VdFqeA45WGqLE+yxSQle2ke5K2NtMz5neLaBGgQEkmU4oh7Eqrv1zr2XzGYNVVe/XCdoHOXr6TzcnwEbYid+4xLekQEeXjw5dK8p6OtJAXWXSAud7Htsf6hEdyKX0UwmbU7b572nAEuBZ+4XtK+kIz/1VE0rW50uJDQOIKjcavTyiQqSmZeikIPM+HGxrMDe0Rtmu9i+ZNuL+JAn6mWZyzDafNzVoMyKH9KNyIEf6utPs4yRNPs
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <101BDCA6F032AB44910391A23B65CFAC@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 5f70f511-a8a4-48c9-a6de-08d7ee9f42e7
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 May 2020 13:46:48.4459 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: fzqhfJ41Ye52YTfiC1hjeqpdtLkcHL58I6YqSWJFoSXEbB6qBscDdqeZeAo76sPB9gv5SOWMp8vik2B8LElXnKyFgm/nlaI552A0JX/FwG4=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM7PR07MB6531
Archived-At: <https://mailarchive.ietf.org/arch/msg/sipcore/yNegBsISTFUg9LzrDC09i5O1glo>
Subject: Re: [sipcore] Draft new version: draft-ietf-sipcore-sip-token-authnz-14 (was: Benjamin Kaduk's Discuss on draft-ietf-sipcore-sip-token-authnz-13)
X-BeenThere: sipcore@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: SIP Core Working Group <sipcore.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sipcore>, <mailto:sipcore-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sipcore/>
List-Post: <mailto:sipcore@ietf.org>
List-Help: <mailto:sipcore-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sipcore>, <mailto:sipcore-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 02 May 2020 13:46:54 -0000

Hi Paul,
    
>    * In section 2.1.1 the edit to the 3rd paragraph has some mis-edits:
>    
>    In "the UAC uses it to to request", s/to to/to/
>
>    In "before the currently used access token expires token", s/expires 
>    token/expires/
>
>    * In section 2.1.2 some more mis-editing: s/makes have use of/makes use of/
  
Will fix everything above.

>    * Section 2.1.2 also says "TLS can still be used for protecting traffic 
>    between SIP endpoints and the AS." This is only true if there is a 
>    direct TLS connection between the endpoint and the AS.  How can that be 
>    assured?
>    
>    Isn't the general point that TLS can be used to secure the content if 
>    the connection is direct between the UAC and the UAS? (But I don't know 
>    how you can assure that other than by knowledge about the network 
>    architecture in which the UAC is operating.
  
Note that the traffic between the SIP endpoints and the AS uses HTTPS (perhaps that could be clarified), which uses TLS. 
  
>    I didn't notice any other issues.
  
Thanks for all your comments and feedback!

Regards,

Christer

    
    On 4/30/20 8:08 AM, Christer Holmberg wrote:
    > Hi,
    > 
    > Based on the IESG reviews, we have submitted a new version (-14) of draft-ietf-sipcore-sip-token-authnz.
    > 
    > We believe and hope that all issues raised in the IESG reviews have been addressed, but please take a look.
    > 
    > A big Thank You for all the comments and suggestions! :)
    > 
    > Regards,
    > 
    > Christer
    > 
    > _______________________________________________
    > sipcore mailing list
    > sipcore@ietf.org
    > https://www.ietf.org/mailman/listinfo/sipcore
    > 
    
    _______________________________________________
    sipcore mailing list
    sipcore@ietf.org
    https://www.ietf.org/mailman/listinfo/sipcore