Re: [Sipping] comments on draft-wing-sipping-spam-score-00

Hannes Tschofenig <Hannes.Tschofenig@gmx.net> Tue, 04 December 2007 17:32 UTC

Return-path: <sipping-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzbdP-0004Ai-H1; Tue, 04 Dec 2007 12:32:39 -0500
Received: from sipping by megatron.ietf.org with local (Exim 4.43) id 1IzbdN-0003ky-8z for sipping-confirm+ok@megatron.ietf.org; Tue, 04 Dec 2007 12:32:37 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzbdM-0003iT-RT for sipping@ietf.org; Tue, 04 Dec 2007 12:32:36 -0500
Received: from mail.gmx.net ([213.165.64.20]) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1IzbdM-0001Vp-CT for sipping@ietf.org; Tue, 04 Dec 2007 12:32:36 -0500
Received: (qmail invoked by alias); 04 Dec 2007 17:32:35 -0000
Received: from dhcp-16ce.ietf70.org (EHLO [130.129.22.206]) [130.129.22.206] by mail.gmx.net (mp058) with SMTP; 04 Dec 2007 18:32:35 +0100
X-Authenticated: #29516787
X-Provags-ID: V01U2FsdGVkX1+SexlY7tqSVwr1mNE5d6y0bbJ9usAbfc4DGV0O8P B7jB8rzooTBlNw
Message-ID: <4755109E.7070506@gmx.net>
Date: Tue, 04 Dec 2007 09:32:30 +0100
From: Hannes Tschofenig <Hannes.Tschofenig@gmx.net>
User-Agent: Thunderbird 2.0.0.9 (Windows/20071031)
MIME-Version: 1.0
To: Jonathan Rosenberg <jdrosen@cisco.com>
Subject: Re: [Sipping] comments on draft-wing-sipping-spam-score-00
References: <47556743.5050604@cisco.com>
In-Reply-To: <47556743.5050604@cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
X-Spam-Score: 1.9 (+)
X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22
Cc: IETF Sipping List <sipping@ietf.org>
X-BeenThere: sipping@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "SIPPING Working Group \(applications of SIP\)" <sipping.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:sipping@ietf.org>
List-Help: <mailto:sipping-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=subscribe>
Errors-To: sipping-bounces@ietf.org

In the past we had the idea to provide the authentication part for the 
Spam score using SAML. That helps if you are verifying more than one 
Spam score and also a Spam score that was generated by a node more than 
one hop away.

Do you think we should re-visit some of that work again?

Ciao
Hannes

Jonathan Rosenberg wrote:
> I think a key part of this is that you need to have a trust 
> relationship with the sender of the score, otherwise its useless. As 
> with any trust relationship, it requires authentication to make sure 
> the guy you are talking to is the one you trust. This typically 
> implies mutual TLS authentication between domains. It also means that 
> you can't have more than one spam score at a time - just the one from 
> the previous hop domain. So how would you authenticate and authorize 
> the sources farther away, as this draft proposes?
>
> It seems that, unless there is a standardized range and meaning of 
> values it will be hard to take any action based on this value.
>
> It would be good to give some examples of how an originating domain 
> might compute the score.
>
> -Jonathan R.



_______________________________________________
Sipping mailing list  https://www1.ietf.org/mailman/listinfo/sipping
This list is for NEW development of the application of SIP
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sip@ietf.org for new developments of core SIP