[stir] DRAFT minutes for STIR 2020-04-20 Interim

Robert Sparks <rjsparks@nostrum.com> Mon, 20 April 2020 15:43 UTC

Return-Path: <rjsparks@nostrum.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B135B3A0A20 for <stir@ietfa.amsl.com>; Mon, 20 Apr 2020 08:43:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.178
X-Spam-Level:
X-Spam-Status: No, score=-0.178 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, T_SPF_HELO_TEMPERROR=0.01, T_SPF_PERMERROR=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nostrum.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id o2itg_K1I7jx for <stir@ietfa.amsl.com>; Mon, 20 Apr 2020 08:43:05 -0700 (PDT)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C79583A09F5 for <stir@ietf.org>; Mon, 20 Apr 2020 08:40:48 -0700 (PDT)
Received: from unescapeable.local ([47.186.30.41]) (authenticated bits=0) by nostrum.com (8.15.2/8.15.2) with ESMTPSA id 03KFeePt073587 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO) for <stir@ietf.org>; Mon, 20 Apr 2020 10:40:42 -0500 (CDT) (envelope-from rjsparks@nostrum.com)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=nostrum.com; s=default; t=1587397242; bh=fLozOy09/2X+ZLrOcpL+u8qPhMmsl5la2E4bsDpM7Bg=; h=To:From:Subject:Date; b=XQOd4a7CsQGI6fFwktm5sMVDN6vW0w3bNc6e9R5BkrUGejU6bIDljuwzHuN8aBJ7v BRSGZ7vdm0K/1uyPQkvWby9ECbnp5BgJdTif92UXM1fYEG+7CHN5HZCMH1WBovdLTj o3u+YMk4xdCLvD6aD+FyGdEU35UWpx61aNd/jKv0=
X-Authentication-Warning: raven.nostrum.com: Host [47.186.30.41] claimed to be unescapeable.local
To: "stir@ietf.org" <stir@ietf.org>
From: Robert Sparks <rjsparks@nostrum.com>
Message-ID: <b2e22a44-6f5f-08e3-2353-a4754e069d72@nostrum.com>
Date: Mon, 20 Apr 2020 10:40:36 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:68.0) Gecko/20100101 Thunderbird/68.7.0
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="------------4C4D1F150AA8CF3141BDE9D7"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/diF0OI_vZTp0Ix4WClHpn8AMSBg>
Subject: [stir] DRAFT minutes for STIR 2020-04-20 Interim
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Apr 2020 15:43:18 -0000

Thanks to Russ for the notes.

The bluesheet section is not yet complete - people were having problems 
with the etherpad. If you were present and haven't already let me know 
by email, please do so ASAP.

------

STIR - Interim meeting - 2020-04-20

Notes
-----

Jon Peterson (Neustar) gave an update on the Out-of-Band document 
(draft-ietf-stir-oob) and the PASSporT Divert document 
(draft-ietf-stir-passport-divert).  The Out-of-Band document is with the 
RFC Editor, and PASSporT Divert got some DISCUSS positions from the IESG 
that need to be resolved.  The main concern is about “div-o” hiding the 
original called number by not including a “div” PASSporT.  The “div-o” 
text needs to be fleshed out a bit more, which would require the 
document to come back to the STIR WG.  The current thought it to 
explicitly state that “opt” is for “Original PASSporT”.

Martin Dolly (AT&T) gave an update on the Assertion Values for a 
Resource Priority Header Claim in Support of Emergency Services Networks 
dcoument (draft-ietf-stir-rph-emergency-services).  References are 
needed for “SOS” addressing, “anonymous”, and “Unregistered UE”.  Expect 
that the document will be ready for WG Last Call in July.

Jon Peterson (Neustar) talked about the Rich Call Data PASSporT 
extension document (draft-ietf-stir-passport-rcd).  Major update was to 
include a “crn” claim that corresponds to a “reason” or string 
representing the intent for a call.  This concept is also discussed in 
draft-wendt-sipcore-callinfo-rcd, which says “this message SHOULD be no 
longer than ten words.”  String is the primary format, but an extensible 
format allows flexibility. Coordination with SIPCORE is needed before 
this document reaches WG Last Call.

Eric Burger (Georgetown University) talked about an IANA registry for 
country-specific STIR Trust Anchors (draft-burger-stir-iana-cert).  
Concerns were expressed during IETF 101 that IANA would need to be an 
arbiter of who gets to put records in registry, but since then Burger 
realized that it does not matter. In real life, illegal robocall 
mitigation is all about reputation and statistics. We know there will be 
calls that have no attestation that are just fine, and we know there 
will be call that will have the highest levels of attestation that are 
illegal robocalls.  STIR increases the confidence in the identifying the 
caller, which can be used to allow, warn, or block the call.  Not 
expecting IANA to figure out who is the responsible organization, 
including delegation, for making or updating a registration.  Rather, 
IANA would confirm valid cryptographic identities.  Te re are not 
privacy concerns since the entries are associated with governments.  The 
suggestion is a “First Come First Served” registry.


BlueSheet
---------
Robert Sparks - AMS
Russ Housley - Vigil Security, LLC
Subir Das - Perspecta Labs
Jon Peterson - Neustar
Murray Kucherawy - Facebook
Ken Carlberg - FCC
David Frankel - ZipDX
Andrew Hutton - Atos
Jack Rickard - Metaswitch
Ben Campbell - Independent
Andy Gallant
Brian Rosen
Eric Burger - Georgetown University
Alissa Cooper  - Cisco
Wilhelm Wimmreuter - InCharge Systems Inc
Martin Dolly - AT&T