Re: [Sipping] Updated version from Functions of SBC draft

Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com> Fri, 29 July 2005 19:27 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DyaVm-0007pm-Qy; Fri, 29 Jul 2005 15:27:14 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DyaVk-0007ph-JW for sipping@megatron.ietf.org; Fri, 29 Jul 2005 15:27:12 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA03033 for <sipping@ietf.org>; Fri, 29 Jul 2005 15:27:10 -0400 (EDT)
Received: from mailgw4.ericsson.se ([193.180.251.62]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Dyb1Q-0003Co-3k for sipping@ietf.org; Fri, 29 Jul 2005 15:59:59 -0400
Received: from esealmw126.eemea.ericsson.se (unknown [153.88.254.123]) by mailgw4.ericsson.se (Symantec Mail Security) with ESMTP id 499E04FF; Fri, 29 Jul 2005 21:27:01 +0200 (CEST)
Received: from esealmw128.eemea.ericsson.se ([153.88.254.172]) by esealmw126.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.211); Fri, 29 Jul 2005 21:27:00 +0200
Received: from mail.lmf.ericsson.se ([131.160.11.50]) by esealmw128.eemea.ericsson.se with Microsoft SMTPSVC(6.0.3790.211); Fri, 29 Jul 2005 21:26:59 +0200
Received: from [131.160.126.9] (rvi2-126-9.lmf.ericsson.se [131.160.126.9]) by mail.lmf.ericsson.se (Postfix) with ESMTP id 79B0E2540; Fri, 29 Jul 2005 22:26:59 +0300 (EEST)
Message-ID: <42EA8302.9040102@ericsson.com>
Date: Fri, 29 Jul 2005 22:26:58 +0300
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla Thunderbird 1.0.5 (Windows/20050711)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: henry@sinnreich.net
Subject: Re: [Sipping] Updated version from Functions of SBC draft
References: <20050727125619.BA9773FC@mailgw1.ericsson.se>
In-Reply-To: <20050727125619.BA9773FC@mailgw1.ericsson.se>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 29 Jul 2005 19:26:59.0928 (UTC) FILETIME=[7D995D80:01C59473]
X-Brightmail-Tracker: AAAAAA==
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 82c9bddb247d9ba4471160a9a865a5f3
Content-Transfer-Encoding: 7bit
Cc: bpenfield@acmepacket.com, alan@jasomi.com, sipping@ietf.org, mbhatia@nextone.com
X-BeenThere: sipping@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "SIPPING Working Group \(applications of SIP\)" <sipping.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:sipping@ietf.org>
List-Help: <mailto:sipping-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=subscribe>
Sender: sipping-bounces@ietf.org
Errors-To: sipping-bounces@ietf.org

Hi Henry,

you are right. We need to expand the security considerations section. In 
the document, we talk about mechanisms that break end-to-end integrity 
or end-to-end authentication... we need to mention those issues again in 
the security considerations sections.

Thanks,

Gonzalo

henry@sinnreich.net wrote:
> This is a useful document and well worth the time.
> 
> In Section 4 "Security Considerations" there is only very cryptic language
> (no pun intended):
> 
>    Many of the functions this document describes have important security
>    and privacy implications.
> 
> This needs to be properly expanded. What are for example the vulnerabilities
> if an SBC is compromised?
> 
> Thanks, Henry
> 
> -----Original Message-----
> From: Jani Hautakorpi (JO/LMF) [mailto:jani.hautakorpi@ericsson.com] 
> Sent: Wednesday, July 27, 2005 4:07 AM
> To: sipping@ietf.org
> Cc: bpenfield@acmepacket.com; alan@jasomi.com;
> Gonzalo.Camarillo@ericsson.com; mbhatia@nextone.com
> Subject: [Sipping] Updated version from Functions of SBC draft
> 
> Hi,
> 
> We have updated the "SIP-Unfriendly Functions in Current Communication 
> Architectures" draft, and it can be fetched from:
> 
> http://www.ietf.org/internet-drafts/draft-camarillo-sipping-sbc-funcs-01.txt
> 
> We've got some feedback from the area director and others, and we have 
> proceeded according to the feedback.
> 
> New version of the draft concentrates strictly to those functions of SBC 
> that break SIP in one way or the other. We believe that it's important to 
> document these functions, and then use these as a foundation for the 
> future work.
> 
> 

-- 
Gonzalo Camarillo         Phone :  +358  9 299 33 71
Oy L M Ericsson Ab        Mobile:  +358 40 702 35 35
Telecom R&D               Fax   :  +358  9 299 30 52
FIN-02420 Jorvas          Email :  Gonzalo.Camarillo@ericsson.com
Finland                   http://www.hut.fi/~gonzalo

_______________________________________________
Sipping mailing list  https://www1.ietf.org/mailman/listinfo/sipping
This list is for NEW development of the application of SIP
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sip@ietf.org for new developments of core SIP