Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: siprec@ietfa.amsl.com
Delivered-To: siprec@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 3D7DD1A01FA;
 Fri,  4 Mar 2016 06:16:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.302
X-Spam-Level: 
X-Spam-Status: No, score=-4.302 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001,
 SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id x-alXFTPbb9R; Fri,  4 Mar 2016 06:16:01 -0800 (PST)
Received: from mercury.scss.tcd.ie (mercury.scss.tcd.ie [134.226.56.6])
 (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 706941A01F6;
 Fri,  4 Mar 2016 06:16:01 -0800 (PST)
Received: from localhost (localhost [127.0.0.1])
 by mercury.scss.tcd.ie (Postfix) with ESMTP id 19260BE55;
 Fri,  4 Mar 2016 14:16:00 +0000 (GMT)
Received: from mercury.scss.tcd.ie ([127.0.0.1])
 by localhost (mercury.scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id IHeXYUEnFjTw; Fri,  4 Mar 2016 14:15:59 +0000 (GMT)
Received: from [134.226.36.93] (bilbo.dsg.cs.tcd.ie [134.226.36.93])
 by mercury.scss.tcd.ie (Postfix) with ESMTPSA id 6ED97BE4D;
 Fri,  4 Mar 2016 14:15:59 +0000 (GMT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; s=mail;
 t=1457100959; bh=qFnDhk0qRVfrhTWWgGW0e56Inx9Q8vxr+ZfzfnX/Q2Y=;
 h=Subject:To:References:Cc:From:Date:In-Reply-To:From;
 b=SXbdcYJZA5CC0XK1es/MoU+Rh7BGovUrmDgVbWSpowzNdQgNypnaMMawZ2D3IFRHQ
 /7P20wRzp2uHep10ZNy5UxywFHd+GsCEg2UdMDntMgbJI+f/Ve8Wt+/W0/6n7+EEB9
 Yn5t3ML5xlm8IJEeYzRqYZfRwXkVXdYWnV9OW/+s=
To: "Ram Mohan R (rmohanr)" <rmohanr@cisco.com>, The IESG <iesg@ietf.org>
References: <20160302110853.23213.23639.idtracker@ietfa.amsl.com>
 <D2FD2694.5326B%rmohanr@cisco.com>
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Openpgp: id=D66EA7906F0B897FB2E97D582F3C8736805F8DA2; url=
Message-ID: <56D9989F.1010103@cs.tcd.ie>
Date: Fri, 4 Mar 2016 14:15:59 +0000
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101
 Thunderbird/38.5.1
MIME-Version: 1.0
In-Reply-To: <D2FD2694.5326B%rmohanr@cisco.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature";
 micalg=sha-256; boundary="------------ms030100060301020101010407"
Archived-At: <http://mailarchive.ietf.org/arch/msg/siprec/n6EEaK9iMVFj3GQxXhEgkqKZXpw>
Cc: "draft-ietf-siprec-metadata@ietf.org"
 <draft-ietf-siprec-metadata@ietf.org>, "siprec@ietf.org" <siprec@ietf.org>,
 "siprec-chairs@ietf.org" <siprec-chairs@ietf.org>
Subject: Re: [siprec] Stephen Farrell's Discuss on
 draft-ietf-siprec-metadata-20: (with DISCUSS and COMMENT)
X-BeenThere: siprec@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SIP Recording Working Group Discussion List <siprec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/siprec>,
 <mailto:siprec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/siprec/>
List-Post: <mailto:siprec@ietf.org>
List-Help: <mailto:siprec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/siprec>,
 <mailto:siprec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 04 Mar 2016 14:16:04 -0000

This is a cryptographically signed message in MIME format.

--------------ms030100060301020101010407
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Hiya,

On 02/03/16 17:51, Ram Mohan R (rmohanr) wrote:
> Hi Stephen,
>=20
> See inline
>=20
> -----Original Message-----
> From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
> Date: Wednesday, 2 March 2016 at 4:38 PM
> To: The IESG <iesg@ietf.org>
> Cc: "draft-ietf-siprec-metadata@ietf.org"
> <draft-ietf-siprec-metadata@ietf.org>, Brian Rosen <br@brianrosen.net>,=

> "siprec-chairs@ietf.org" <siprec-chairs@ietf.org>, Brian Rosen
> <br@brianrosen.net>, "siprec@ietf.org" <siprec@ietf.org>
> Subject: Stephen Farrell's Discuss on draft-ietf-siprec-metadata-20: (w=
ith
> DISCUSS and COMMENT)
>=20
>> Stephen Farrell has entered the following ballot position for
>> draft-ietf-siprec-metadata-20: Discuss
>>
>> When responding, please keep the subject line intact and reply to all
>> email addresses included in the To and CC lines. (Feel free to cut thi=
s
>> introductory paragraph, however.)
>>
>>
>> Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.h=
tml
>> for more information about IESG DISCUSS and COMMENT positions.
>>
>>
>> The document, along with other ballot positions, can be found here:
>> https://datatracker.ietf.org/doc/draft-ietf-siprec-metadata/
>>
>>
>>
>> ----------------------------------------------------------------------=

>> DISCUSS:
>> ----------------------------------------------------------------------=

>>
>>
>>
>> (1) In section 10 you have a MUST for integrity and confid,
>> which is good, but then RECOMMEND S/MIME, which is, I think,
>> mythical. Wouldn't it be better to reflect reality
>> (hop-by-hop TLS) and then say what actual security
>> considerations arise, e.g. who might be on the path and how
>> can they (mis)behave?
>=20
> Yes. This needs some changes. After the discussions with SecDir we thou=
ght
> it would be good to refer to Security Consideration section of protocol=

> draft (section 12 general and 12.1 of
> https://tools.ietf.org/html/draft-ietf-siprec-protocol-18#page-38). 12.=
1
> covers the TLS the mutual Authentication and also talk about who else c=
an
> be in the path (para 2).
>=20
> Since the metadata is always going to be carried as a body in the
> protocol, all the considerations there are equally applicable here.
>=20
> With this the proposed text for Security consideration in this draft wo=
uld
> be:
>=20
> NEW:
> The procedures mentioned in security consideration section of
> [I-D.ietf-siprec-protocol] MUST be implemented by SRC and SRS
> for mutual authentication.
> Some implementations may have the SRC choose parts of metadata that
>      can be sent to the SRS.  In other cases, SRCs may send metadata th=
at
>      is not appropriate for the SRS to record.  Which metadata is actua=
lly
>      recorded by the SRS must be carefully considered to balance privac=
y
>      concerns with usability.  Implementations MUST control what metada=
ta
>      is recorded, and MUST NOT save metadata sent by the SRC that does =
not
>      conform to the recording policy of the SRS.  Metadata in storage
>      needs to be provided with a level of security that is comparable t=
o
>      that of the recording session.
>=20
>=20
> Would this be better ? Or else we will have to replicate most of the te=
xt
> from Protocol to here again.

Yes, that's good, and no I'd not replicate text from the protocol
spec, your reference with a MUST above is fine. (I re-read the
security considerations of the protocol spec, and I think it covers
things well enough.)

Thanks,
S.

>=20
>=20
> Ram
>>
>> (2) 6.10: Don't you need to say to use UUID version 4 with
>> random numbers and to not use MAC addresses?  IOW, refer to
>> RFC4122, Section 4.4 for how to generate UUIDs.
>>
>> Note that issues related to both of the above were part
>> of the discussion that ensued from the secdir review. [1]
>>
>>   [1] https://www.ietf.org/mail-archive/web/secdir/current/msg06370.ht=
ml
>>
>>
>> ----------------------------------------------------------------------=

>> COMMENT:
>> ----------------------------------------------------------------------=

>>
>>
>>
>> - section 4, last para: How could an SRC know this and hence
>> what it's safe to omit?
>>
>> - 6.9: I would have thought that more precision about
>> fractional seconds support would be useful here, or else, to
>> just say that you're limiting to single-second granularity.
>> Wouldn't doing one or the other be better? Otherwise you
>> might get different s/w ordering events in different orders
>> unexpectedly.
>>
>>
>=20


--------------ms030100060301020101010407
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCC
CvIwggUIMIID8KADAgECAhBPzaE7pzYviUJyhmHTFBdnMA0GCSqGSIb3DQEBCwUAMHUxCzAJ
BgNVBAYTAklMMRYwFAYDVQQKEw1TdGFydENvbSBMdGQuMSkwJwYDVQQLEyBTdGFydENvbSBD
ZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEjMCEGA1UEAxMaU3RhcnRDb20gQ2xhc3MgMSBDbGll
bnQgQ0EwHhcNMTYwMjA5MDkyODE1WhcNMTcwMjA5MDkyODE1WjBOMSIwIAYDVQQDDBlzdGVw
aGVuLmZhcnJlbGxAY3MudGNkLmllMSgwJgYJKoZIhvcNAQkBFhlzdGVwaGVuLmZhcnJlbGxA
Y3MudGNkLmllMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtuC0rYze/2JinSra
C9F2RjGdQZjNALLcW9C3WKTwYII3wBslobmHuPEYE5JaGItmzuKnAW619R1rD/kfoNWC19N3
rBZ6UX9Cmb9D9exCwYIwVuSwjrCQWGxgCtNQTrwKzCCpI790GRiMTvxvO7UmzmBrCaBLiZW5
R0fBjK5Yn6hUhAzGBkNbkIEL28cLJqH0yVz7Kl92OlzrQqTPEts5m6cDnNdY/ADfeAX18c1r
dxZqcAxhLotrCqgsVA4ilbQDMMXGTLlB5TP35HeWZuGBU7xu003rLcFLdOkD8xvpJoYZy9Kt
3oABXPS5yqtMK+XCNdqmMn+4mOtLwQSMmPCSiQIDAQABo4IBuTCCAbUwCwYDVR0PBAQDAgSw
MB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDBDAJBgNVHRMEAjAAMB0GA1UdDgQWBBQJ
QhvwQ5Fl372Z6xqo6fdn8XejTTAfBgNVHSMEGDAWgBQkgWw5Yb5JD4+3G0YrySi1J0htaDBv
BggrBgEFBQcBAQRjMGEwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLnN0YXJ0c3NsLmNvbTA5
BggrBgEFBQcwAoYtaHR0cDovL2FpYS5zdGFydHNzbC5jb20vY2VydHMvc2NhLmNsaWVudDEu
Y3J0MDgGA1UdHwQxMC8wLaAroCmGJ2h0dHA6Ly9jcmwuc3RhcnRzc2wuY29tL3NjYS1jbGll
bnQxLmNybDAkBgNVHREEHTAbgRlzdGVwaGVuLmZhcnJlbGxAY3MudGNkLmllMCMGA1UdEgQc
MBqGGGh0dHA6Ly93d3cuc3RhcnRzc2wuY29tLzBGBgNVHSAEPzA9MDsGCysGAQQBgbU3AQIE
MCwwKgYIKwYBBQUHAgEWHmh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL3BvbGljeTANBgkqhkiG
9w0BAQsFAAOCAQEArzrSv2C8PlBBmGuiGrzm2Wma46/KHtXmZYS0bsd43pM66Pc/MsqPE0HD
C1GzMFfwB6BfkJn8ijNSIhlgj898WzjvnpM/SO8KStjlB8719ig/xKISrOl5mX55XbFlQtX9
U6MrqRgbDIATxhD9IDr+ryvovDzChqgQj7mt2jYr4mdlRjsjod3H1VY6XglRmaaNGZfsCARM
aE/TU5SXIiqauwt5KxNGYAY67QkOBs7O1FkSXpTk7+1MmzJMF4nP8QQ5n8vhVNseF+/Wm7ai
9mtnrkLbaznMsy/ULo/C2yuLUWTbZZbf4EKNmVdme6tUDgYkFjAFOblfA7W1fSPiQGagYzCC
BeIwggPKoAMCAQICEGunin0K14jWUQr5WeTntOEwDQYJKoZIhvcNAQELBQAwfTELMAkGA1UE
BhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKzApBgNVBAsTIlNlY3VyZSBEaWdpdGFs
IENlcnRpZmljYXRlIFNpZ25pbmcxKTAnBgNVBAMTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24g
QXV0aG9yaXR5MB4XDTE1MTIxNjAxMDAwNVoXDTMwMTIxNjAxMDAwNVowdTELMAkGA1UEBhMC
SUwxFjAUBgNVBAoTDVN0YXJ0Q29tIEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmlj
YXRpb24gQXV0aG9yaXR5MSMwIQYDVQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL192vfDon2D9luC/dtbX64eG3XAtRmv
mCSsu1d52DXsCR58zJQbCtB2/A5uFqNxWacpXGGtTCRk9dEDBlmixEd8QiLkUfvHpJX/xKnm
VkS6Iye8wUbYzMsDzgnpazlPg19dnSqfhM+Cevdfa89VLnUztRr2cgmCfyO9Otrh7LJDPG+4
D8ZnAqDtVB8MKYJL6QgKyVhhaBc4y3bGWxKyXEtx7QIZZGxPwSkzK3WIN+VKNdkiwTubW5PI
dopmykwvIjLPqbJK7yPwFZYekKE015OsW6FV+s4DIM8UlVS8pkIsoGGJtMuWjLL4tq2hYQuu
N0jhrxK1ljz50hH23gA9cbMCAwEAAaOCAWQwggFgMA4GA1UdDwEB/wQEAwIBBjAdBgNVHSUE
FjAUBggrBgEFBQcDAgYIKwYBBQUHAwQwEgYDVR0TAQH/BAgwBgEB/wIBADAyBgNVHR8EKzAp
MCegJaAjhiFodHRwOi8vY3JsLnN0YXJ0c3NsLmNvbS9zZnNjYS5jcmwwZgYIKwYBBQUHAQEE
WjBYMCQGCCsGAQUFBzABhhhodHRwOi8vb2NzcC5zdGFydHNzbC5jb20wMAYIKwYBBQUHMAKG
JGh0dHA6Ly9haWEuc3RhcnRzc2wuY29tL2NlcnRzL2NhLmNydDAdBgNVHQ4EFgQUJIFsOWG+
SQ+PtxtGK8kotSdIbWgwHwYDVR0jBBgwFoAUTgvvGqRAW6UXaYcwyjRoQ9BBrvIwPwYDVR0g
BDgwNjA0BgRVHSAAMCwwKgYIKwYBBQUHAgEWHmh0dHA6Ly93d3cuc3RhcnRzc2wuY29tL3Bv
bGljeTANBgkqhkiG9w0BAQsFAAOCAgEAi+P3h+wBi4StDwECW5zhIycjBL008HACblIf26HY
0JdOruKbrWDsXUsiI0j/7Crft9S5oxvPiDtVqspBOB/y5uzSns1lZwh7sG96bYBZpcGzGxpF
NjDmQbcM3yl3WFIRS4WhNrsOY14V7y2IrUGsvetsD+bjyOngCIVeC/GmsmtbuLOzJ606tEc9
uRbhjTu/b0x2Fo+/e7UkQvKzNeo7OMhijixaULyINBfCBJb+e29bLafgu6JqjOUJ9eXXj20p
6q/CW+uVrZiSW57+q5an2P2i7hP85jQJcy5j4HzA0rSiF3YPhKGAWUxKPMAVGgcYoXzWydOv
Z3UDsTDTagXpRDIKQLZo02wrlxY6iMFqvlzsemVf1odhQJmi7Eh5TbxI40kDGcBOBHhwnaOu
mZhLP+SWJQnjpLpSlUOj95uf1zo9oz9e0NgIJoz/tdfrBzez76xtDsK0KfUDHt1/q59BvDI7
RX6gVr0fQoCyMczNzCTcRXYHY0tq2J0oT+bsb6sH2b4WVWAiJKnSYaWDjdA70qHX4mq9MIjO
/ZskmSY8wtAk24orAc0vwXgYanqNsBX5Yv4sN4Z9VyrwMdLcusP7HJgRdAGKpkR2I9U4zEsN
JQJewM7S4Jalo1DyPrLpL2nTET8ZrSl5Utp1UeGp/2deoprGevfnxWB+vHNQiu85o6MxggPM
MIIDyAIBATCBiTB1MQswCQYDVQQGEwJJTDEWMBQGA1UEChMNU3RhcnRDb20gTHRkLjEpMCcG
A1UECxMgU3RhcnRDb20gQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxIzAhBgNVBAMTGlN0YXJ0
Q29tIENsYXNzIDEgQ2xpZW50IENBAhBPzaE7pzYviUJyhmHTFBdnMA0GCWCGSAFlAwQCAQUA
oIICEzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNjAzMDQx
NDE1NTlaMC8GCSqGSIb3DQEJBDEiBCDJOz15wvpBteMVkWH2aVA20I1jf5JiEr1DmHk7lxlk
CDBsBgkqhkiG9w0BCQ8xXzBdMAsGCWCGSAFlAwQBKjALBglghkgBZQMEAQIwCgYIKoZIhvcN
AwcwDgYIKoZIhvcNAwICAgCAMA0GCCqGSIb3DQMCAgFAMAcGBSsOAwIHMA0GCCqGSIb3DQMC
AgEoMIGaBgkrBgEEAYI3EAQxgYwwgYkwdTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0
Q29tIEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSMw
IQYDVQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQQIQT82hO6c2L4lCcoZh0xQXZzCB
nAYLKoZIhvcNAQkQAgsxgYyggYkwdTELMAkGA1UEBhMCSUwxFjAUBgNVBAoTDVN0YXJ0Q29t
IEx0ZC4xKTAnBgNVBAsTIFN0YXJ0Q29tIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MSMwIQYD
VQQDExpTdGFydENvbSBDbGFzcyAxIENsaWVudCBDQQIQT82hO6c2L4lCcoZh0xQXZzANBgkq
hkiG9w0BAQEFAASCAQA8Hf73xBDubDrz+y+yQSOS8fymv+BKQlIk1SwnZ2qqAJLbrW1fgWNB
PDQaCG5GSqsfC3Ll3tvN+A4qeQ9gYDEQmB7tRuplCeLgxZLrRZFglHHM2OmnabsnRZR7kPxQ
AHcYf+3obtQe4C1vwBMxeLtA5kqriZxeEGvnHphwxRO5byUgyCggum9bt9dysC1QnL8peyc+
ng04hDn/0TrHqyhG12aIEfXPbb0Nb6lPoifbjqTQVVgy54sinTV9oNFw1DrgK1+tWaqvNSv1
svu+5dfzY1691mSifSNLcGWlR6sT0S0g831LXCb1/SKDFK6uR5m2nLBQ6zbxryrmW3M+FsTp
AAAAAAAA
--------------ms030100060301020101010407--

