[siprec] Stephen Farrell's Discuss on draft-ietf-siprec-metadata-20: (with DISCUSS and COMMENT)

"Stephen Farrell" <stephen.farrell@cs.tcd.ie> Wed, 02 March 2016 11:08 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: siprec@ietf.org
Delivered-To: siprec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 2BCA51AD0AE; Wed, 2 Mar 2016 03:08:53 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.15.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20160302110853.23213.23639.idtracker@ietfa.amsl.com>
Date: Wed, 02 Mar 2016 03:08:53 -0800
Archived-At: <http://mailarchive.ietf.org/arch/msg/siprec/5KinJwyUYLt8PFJnkBkP1mHLtFE>
Cc: draft-ietf-siprec-metadata@ietf.org, siprec@ietf.org, siprec-chairs@ietf.org
Subject: [siprec] Stephen Farrell's Discuss on draft-ietf-siprec-metadata-20: (with DISCUSS and COMMENT)
X-BeenThere: siprec@ietf.org
X-Mailman-Version: 2.1.15
List-Id: SIP Recording Working Group Discussion List <siprec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/siprec>, <mailto:siprec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/siprec/>
List-Post: <mailto:siprec@ietf.org>
List-Help: <mailto:siprec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/siprec>, <mailto:siprec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Mar 2016 11:08:53 -0000

Stephen Farrell has entered the following ballot position for
draft-ietf-siprec-metadata-20: Discuss

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-siprec-metadata/



----------------------------------------------------------------------
DISCUSS:
----------------------------------------------------------------------



(1) In section 10 you have a MUST for integrity and confid,
which is good, but then RECOMMEND S/MIME, which is, I think,
mythical. Wouldn't it be better to reflect reality
(hop-by-hop TLS) and then say what actual security
considerations arise, e.g. who might be on the path and how
can they (mis)behave?

(2) 6.10: Don't you need to say to use UUID version 4 with
random numbers and to not use MAC addresses?  IOW, refer to
RFC4122, Section 4.4 for how to generate UUIDs. 

Note that issues related to both of the above were part
of the discussion that ensued from the secdir review. [1]

   [1] https://www.ietf.org/mail-archive/web/secdir/current/msg06370.html


----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------



- section 4, last para: How could an SRC know this and hence
what it's safe to omit?

- 6.9: I would have thought that more precision about
fractional seconds support would be useful here, or else, to
just say that you're limiting to single-second granularity.
Wouldn't doing one or the other be better? Otherwise you
might get different s/w ordering events in different orders
unexpectedly.