Return-Path: <ron.even.tlv@gmail.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id 7DA2F3A635F; Tue, 14 Jul 2009 15:01:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.165
X-Spam-Level: 
X-Spam-Status: No, score=-2.165 tagged_above=-999 required=5 tests=[AWL=0.433,
 BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mdfQN+LUIwT3;
 Tue, 14 Jul 2009 15:01:41 -0700 (PDT)
Received: from mail-fx0-f218.google.com (mail-fx0-f218.google.com
 [209.85.220.218]) by core3.amsl.com (Postfix) with ESMTP id A6F433A6E60;
 Tue, 14 Jul 2009 15:01:24 -0700 (PDT)
Received: by fxm18 with SMTP id 18so3101102fxm.37 for <multiple recipients>;
 Tue, 14 Jul 2009 15:00:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma;
 h=domainkey-signature:received:received:from:to:cc:references
 :in-reply-to:subject:date:message-id:mime-version:content-type
 :x-mailer:thread-index:content-language;
 bh=jKIvUZ2UzofS+UNKUoF/lXaPGvA3D8jZA8LscnDzTUI=;
 b=a0hN5icK67E/9U7kdht3MmSc2ZNYXfMRUzg/4oXhib0JpwSio3gwQOPg70Kf/5s8H5
 YhX9CvijbG7ZNGHMXvFbPX7OzOHplal2wgfudMGArU5oRorX6Az4m1wDXOioTt1s/ArA
 kS3UNvsSO6tj60ges99fhz2lBp4fKJDx1gnz8=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma;
 h=from:to:cc:references:in-reply-to:subject:date:message-id
 :mime-version:content-type:x-mailer:thread-index:content-language;
 b=GVe0Eanxh9srxlnumxNB/mwvqUlNoZNK1pqnFPbhG2avak2ZqIc4ghzH8pFAQZG2ZI
 znEJ2Zw+WUVyI7uNeffnNAPFd4uDgEK2LMrzw0zGN/wa8YjDdTb1lKuDNsLWT1Tbr40g
 2pyOOffHG2j7zXzLpRe09+rJ5FsPehXdp+JsU=
Received: by 10.103.131.13 with SMTP id i13mr3715652mun.64.1247607397188;
 Tue, 14 Jul 2009 14:36:37 -0700 (PDT)
Received: from windows8d787f9 (bzq-79-179-66-37.red.bezeqint.net
 [79.179.66.37]) by mx.google.com with ESMTPS id
 n10sm30032606mue.17.2009.07.14.14.36.34 (version=TLSv1/SSLv3 cipher=RC4-MD5);
 Tue, 14 Jul 2009 14:36:36 -0700 (PDT)
From: "Roni Even" <ron.even.tlv@gmail.com>
To: "'Dan York'" <dyork@voxeo.com>
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>	<EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>	<05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
 <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com>
 <4a5cf0da.190c660a.3ec0.58fa@mx.google.com>
 <F692C744-B56F-4053-BD76-4D63B61C2C48@voxeo.com>
In-Reply-To: <F692C744-B56F-4053-BD76-4D63B61C2C48@voxeo.com>
Date: Wed, 15 Jul 2009 00:36:08 +0300
Message-ID: <4a5cfa64.0aa5660a.1918.ffff94d6@mx.google.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_0A87_01CA04E4.4014F3D0"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcoEx4wp7NhipJKURgG7lWCJ5mWaSgAAykQQ
Content-Language: en-us
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org,
 'Roni Even' <Even.roni@huawei.com>
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>,
 <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>,
 <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 22:01:43 -0000

This is a multi-part message in MIME format.

------=_NextPart_000_0A87_01CA04E4.4014F3D0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Dan,

I prefer the text that recommends SRTP (It is a SHOULD and not a MUST). The
text we currently have is based on the security reviews we got for RTP
payload specifications, and as you can see it addresses the issue of why not
to mandate SRTP.

Roni

 

From: Dan York [mailto:dyork@voxeo.com] 
Sent: Wednesday, July 15, 2009 12:11 AM
To: Roni Even
Cc: 'Roni Even'; 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan
Shanmugham'; rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

So as the RAI reviewer, are you okay with the text I suggested:

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Or would you prefer this text that includes the recommendation of SRTP?
(Which I noticed you did in the RTP payloads spec - and it makes sense to me
to provide some basic guidance.):

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. If appropriate, usage of the Secure Real-time
Transport Protocol (SRTP) [RFC3711] is recommended.

------

 

Regards,

Dan

 

Regards,

Dan

 

On Jul 14, 2009, at 4:55 PM, Roni Even wrote:





Dan,

This is the general idea. The major reason is that there are various ways to
protect the data and if you are not mandating one for interoperability then
it can be more general

 

For example we have the following text when discussing security in the RTP
payloads specifications.

 

RTP packets using the payload format defined in this specification

   are subject to the security considerations discussed in the RTP

   specification [RFC3550] and any appropriate RTP profile.  The main

   security considerations for the RTP packet carrying the RTP payload

   format defined within this memo are confidentiality, integrity, and

   source authenticity.  Confidentiality is achieved by encryption of

   the RTP payload.  Integrity of the RTP packets is achieved through a

   suitable cryptographic integrity protection mechanism.  Such a

   cryptographic system may also allow the authentication of the source

   of the payload.  A suitable security mechanism for this RTP payload

   format should provide confidentiality, integrity protection, and at

   least source authentication capable of determining if an RTP packet

   is from a member of the RTP session.

 

   Note that the appropriate mechanism to provide security to RTP and

   payloads following this memo may vary.  It is dependent on the

   application, the transport, and the signaling protocol employed.

   Therefore, a single mechanism is not sufficient, although if

   suitable, usage of the Secure Real-time Transport Protocol (SRTP)

   [RFC3711] recommended.  Other mechanisms that may be used are IPsec

   [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over TCP);

   other alternatives may exist.

 

Roni Even

 

From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On Behalf Of Dan
York
Sent: Tuesday, July 14, 2009 11:16 PM
To: Roni Even
Cc: 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham';
rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

The current text at
http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 is:

------
12.3. Media session protection  
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances and the output of
text-to-speech operations. MRCPv2 servers MUST support SRTP for protection
of audio media sessions. MRCPv2 clients that originate or consume audio
similarly MUST support SRTP. Alternative media channel protection MAY be
used if desired (e.g. IPSEC).

------

 

Based on your comments and the srtp-not-mandatory draft (which was just
revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03
), my understanding would be that you are advocating something more like
this:

 

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Is that an accurate summary of your feedback?  Would that text be
acceptable?

 

Regards,

Dan

 

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:






Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be  not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft

Roni





-----Original Message-----

From: Eric Burger [mailto:eburger@standardstrack.com]

Sent: Thursday, July 09, 2009 11:28 PM

To: Roni Even

Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;

rai@ietf.org

Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19

 

The reality is that NO ONE has implemented any security to date. The

GENART reviewer raised the same issue, and so far the work group has

the same response: MRCPv2 (the speechsc work group) is not planning on

figuring out which of the seven key exchange mechanisms to use in

SIP.  We are counting on the community publishing something, and

people using it.  After all, we are the "using SIP for media resource

control" work group, not the "media resource control work group using

something like SIP for control."

 

Does this work for you?

 

On Jul 7, 2009, at 3:40 PM, Roni Even wrote:

 

[snip]

 

 

18.   In section 12.3 the suggestion is to use SRTP as the mandatory

interoperability mode. If the reason for mandating SRTP is for a

common mode you should also decide on a key exchange mechanism. I

suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-

not-mandatory-02

for discussion on media security.



_______________________________________________
RAI mailing list
RAI@ietf.org
https://www.ietf.org/mailman/listinfo/rai

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 






 

 

 

 

 

 

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 





 

 

 

 

 

 


------=_NextPart_000_0A87_01CA04E4.4014F3D0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-webkit-nbsp-mode: space;-webkit-line-break: after-white-space'>

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Dan,<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I prefer the text that recommends SRTP (It is a SHOULD =
and not a
MUST). The text we currently have is based on the security reviews we =
got for
RTP payload specifications, and as you can see it addresses the issue of =
why
not to mandate SRTP.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Roni<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> Dan York
[mailto:dyork@voxeo.com] <br>
<b>Sent:</b> Wednesday, July 15, 2009 12:11 AM<br>
<b>To:</b> Roni Even<br>
<b>Cc:</b> 'Roni Even'; 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan
Shanmugham'; rai@ietf.org<br>
<b>Subject:</b> Re: [RAI] RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></p>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>Roni,<o:p></o:p></p>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>So as the RAI reviewer, are you okay with the text =
I
suggested:<o:p></o:p></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif"'>12.3. Media session =
protection&nbsp;</span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Or would you prefer this text that includes the
recommendation of SRTP? &nbsp;(Which I noticed you did in the RTP =
payloads spec
- and it makes sense to me to provide some basic =
guidance.):<o:p></o:p></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif"'>12.3. Media session =
protection&nbsp;</span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the audio. If =
appropriate,&nbsp;usage of the Secure Real-time Transport Protocol =
(SRTP)&nbsp;[RFC3711] is =
recommended.</span></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Regards,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal>Dan<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Regards,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal>Dan<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal>On Jul 14, 2009, at 4:55 PM, Roni Even =
wrote:<o:p></o:p></p>

</div>

<p class=3DMsoNormal><br>
<br>
<o:p></o:p></p>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Dan,</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>This is the general idea. The major reason is that there =
are
various ways to protect the data and if you are not mandating one for
interoperability then it can be more general</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>For example we have the following text when discussing =
security
in the RTP payloads specifications.</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>RTP packets using the payload format defined in this
specification</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; are subject to the security considerations
discussed in the RTP</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; specification [RFC3550] and any appropriate =
RTP
profile.&nbsp; The main</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; security considerations for the RTP packet =
carrying
the RTP payload</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format defined within this memo are
confidentiality, integrity, and</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; source authenticity.&nbsp; Confidentiality =
is
achieved by encryption of</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; the RTP payload.&nbsp; Integrity of the RTP =
packets
is achieved through a</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable cryptographic integrity protection
mechanism.&nbsp; Such a</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; cryptographic system may also allow the
authentication of the source</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; of the payload.&nbsp; A suitable security =
mechanism
for this RTP payload</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format should provide confidentiality, =
integrity
protection, and at</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; least source authentication capable of =
determining
if an RTP packet</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; is from a member of the RTP =
session.</span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Note that the appropriate mechanism to =
provide
security to RTP and</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; payloads following this memo may vary.&nbsp; =
It is dependent
on the</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; application, the transport, and the =
signaling
protocol employed.</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Therefore, a single mechanism is not =
sufficient,
although if</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable, usage of the Secure Real-time =
Transport
Protocol (SRTP)</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC3711] recommended.&nbsp; Other =
mechanisms that
may be used are IPsec</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC4301] Transport Layer Security (TLS) =
[RFC5246]
(RTP over TCP);</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; other alternatives may exist.</span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Roni Even</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt;
border-width:initial;border-color:initial'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in;
border-width:initial;border-color:initial'>

<div>

<p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";
color:black'>From:</span></b><span class=3Dapple-converted-space><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a
href=3D"mailto:rai-bounces@ietf.org">rai-bounces@ietf.org</a> [<a
href=3D"mailto:rai-bounces@ietf.org">mailto:rai-bounces@ietf.org</a>]<spa=
n
class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span
class=3Dapple-converted-space>&nbsp;</span></b>Dan York<br>
<b>Sent:</b><span class=3Dapple-converted-space>&nbsp;</span>Tuesday, =
July 14,
2009 11:16 PM<br>
<b>To:</b><span class=3Dapple-converted-space>&nbsp;</span>Roni Even<br>
<b>Cc:</b><span class=3Dapple-converted-space>&nbsp;</span>'Daniel =
Burnett';<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;
'Saravanan Shanmugham';<span =
class=3Dapple-converted-space>&nbsp;</span><a
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><br>
<b>Subject:</b><span class=3Dapple-converted-space>&nbsp;</span>Re: =
[RAI] RAI
review of draft-ietf-speechsc-mrcpv2-19</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Roni,<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>The current text =
at&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-=
12.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12=
.3</a><span
class=3Dapple-converted-space>&nbsp;</span>is:<o:p></o:p></span></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif";color:black'>------</span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";color:black=
'>12.3. Media session protection&nbsp; </span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";color:black=
'>Sensitive data is also carried on media sessions terminating on MRCPv2 =
servers (the other end of a media channel may or may not be on the =
MRCPv2 client). This data includes the user's spoken utterances and the =
output of text-to-speech operations. MRCPv2 servers MUST support SRTP =
for protection of audio media sessions. MRCPv2 clients that originate or =
consume audio similarly MUST support SRTP. Alternative media channel =
protection MAY be used if desired (e.g. IPSEC).</span></span><span
style=3D'color:black'><o:p></o:p></span></pre></div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Based on your comments =
and the
srtp-not-mandatory draft (which was just revised to&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">=
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a><span
class=3Dapple-converted-space>&nbsp;</span>), my understanding would be =
that you
are advocating something more like this:<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:12.0pt;
font-family:"Helvetica","sans-serif";color:black'>12.3. Media session =
protection&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:12.0pt;font-family:"Helvetica","sans-serif";color:blac=
k'>Sensitive data is also carried on media sessions terminating on =
MRCPv2 servers (the other end of a media channel may or may not be on =
the MRCPv2 client). This data includes the user's spoken utterances =
&nbsp; &nbsp;and the output of text-to-speech operations. MRCPv2 servers =
MUST support a security mechanism for protection of audio media =
sessions. MRCPv2 clients that originate or consume audio similarly MUST =
support a security mechanism for protection of the =
audio.&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></pre></div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Is that an accurate =
summary of
your feedback? &nbsp;Would that text be =
acceptable?<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Regards,<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Dan<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>On Jul 9, 2009, at 4:56 =
PM, Roni
Even wrote:<o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><br>
<br>
<br>
<o:p></o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Eric,<br>
My comment is that in this case in AVT we say that you do not need =
to<br>
mandate SRTP but mandate a security mechanism that can be &nbsp;not only =
SRTP
but<br>
in a different layer like ipsec. This is why I gave a reference to =
the<br>
srtp-not-mandatory draft<br>
<br>
Roni<br>
<br>
<br>
<br>
<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>-----Original =
Message-----<o:p></o:p></span></p>

</div>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>From: Eric Burger [<a
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.=
com</a>]<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Sent: Thursday, July =
09, 2009
11:28 PM<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>To: Roni =
Even<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Cc: Saravanan =
Shanmugham; Daniel
Burnett;<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<o:p></o:p></span=
></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Subject: Re: RAI review =
of
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>The reality is that NO =
ONE has
implemented any security to date. The<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>GENART reviewer raised =
the same
issue, and so far the work group has<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>the same response: =
MRCPv2 (the
speechsc work group) is not planning on<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>figuring out which of =
the seven
key exchange mechanisms to use in<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>SIP. &nbsp;We are =
counting on the
community publishing something, and<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>people using it. =
&nbsp;After all,
we are the &quot;using SIP for media resource<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>control&quot; work =
group, not the
&quot;media resource control work group using<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>something like SIP for =
control.&quot;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Does this work for =
you?<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>On Jul 7, 2009, at 3:40 =
PM, Roni
Even wrote:<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>[snip]<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>18. &nbsp;&nbsp;In =
section 12.3
the suggestion is to use SRTP as the mandatory<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>interoperability mode. =
If the
reason for mandating SRTP is for a<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>common mode you should =
also decide
on a key exchange mechanism. I<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>suggest you look at<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.iet=
f.org/html/draft-ietf-avt-srtp-</a><o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>not-mandatory-02<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>for discussion on media =
security.<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><br>
<br>
_______________________________________________<br>
RAI mailing list<br>
<a href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>
<a =
href=3D"https://www.ietf.org/mailman/listinfo/rai">https://www.ietf.org/m=
ailman/listinfo/rai</a><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>--&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Dan York, Director of Conversations</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Voxeo Corporation<span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Phone: +1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Join the Voxeo conversation:</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Blogs:<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Twitter:<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a><span
class=3Dapple-converted-space>&nbsp;</span>&nbsp;<a
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></span>=
<span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Facebook:<span =
class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
/span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><br>
<br>
<br>
</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

</div>

</div>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>--&nbsp;<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Dan York, Director of Conversations<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Voxeo Corporation<span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a><o:p></o:p></span></p>=


</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Phone: +1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Join the Voxeo conversation:<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a><o:p></o:p></sp=
an></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a>
&nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a><o:p></=
o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><br>
<br>
<o:p></o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</div>

</div>

</body>

</html>

------=_NextPart_000_0A87_01CA04E4.4014F3D0--

