[stir] STIR's basic operational model with SIP

Dave Crocker <dhc@dcrocker.net> Tue, 09 August 2016 15:11 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A26EF12D8BF for <stir@ietfa.amsl.com>; Tue, 9 Aug 2016 08:11:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.209
X-Spam-Level:
X-Spam-Status: No, score=-1.209 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RDNS_NONE=0.793, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=dcrocker.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eqOIXGLZuWne for <stir@ietfa.amsl.com>; Tue, 9 Aug 2016 08:11:58 -0700 (PDT)
Received: from simon.songbird.com (unknown [72.52.113.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 13D6C12D8BD for <stir@ietf.org>; Tue, 9 Aug 2016 08:11:58 -0700 (PDT)
Received: from [192.168.1.168] (76-218-8-128.lightspeed.sntcca.sbcglobal.net [76.218.8.128]) (authenticated bits=0) by simon.songbird.com (8.14.4/8.14.4/Debian-4.1ubuntu1) with ESMTP id u79FC0MY010098 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NOT) for <stir@ietf.org>; Tue, 9 Aug 2016 08:12:00 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=dcrocker.net; s=default; t=1470755520; bh=RTZeCVwMhgT2CBDu5042Xtk/VCYCBZa5mvVOozK1YKo=; h=From:Subject:To:Reply-To:Date:From; b=i/Lz57jj405pCpq+XEVdogIK4CK7lbKXYdfppD//Zlk+LbudVJKrgjEQFmE8P9rYE tiNOyws/terfv5BBgFqNvJgSa41GfBsR/3++ikDc/nvGeARscZb93e2MtQcFGYQ6zz J0VIFPMFbCFkLwo4VzMInG3M4NT/1C5tu0jthE+A=
From: Dave Crocker <dhc@dcrocker.net>
Organization: Brandenburg InternetWorking
To: "stir@ietf.org" <stir@ietf.org>
Message-ID: <3e59df1a-741a-9d3a-71fc-203015efbe0b@dcrocker.net>
Date: Tue, 09 Aug 2016 08:11:31 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.2.0
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/m0Z-WnW0SXYO1JeFQU8QRTpD_4o>
Subject: [stir] STIR's basic operational model with SIP
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: dcrocker@bbiw.net
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Aug 2016 15:11:58 -0000

Folks,

 From what I've been told offline -- but which is not explicitly 
documented in the specifications -- the intended operational framework 
for these specifications is amongst a relatively small set of service 
providers.  That is, the community of folk who are regulated and/or used 
to doing business with bilateral agreements.

This appears to produce an expectation of a service infrastructure for 
STIR that is not public.  That is, the query service for obtaining keys 
and key validation information will not be accessible to random users 
over the open Internet.

For the SIP-based portion of the validation service, this means that a 
caller or a callee with their own SIP clients will not be able to 
participate in the validation process.

If that is not correct, would someone please explain?

If it is correct, why is that an acceptable operational choice for a SIP 
service?

d/
-- 

   Dave Crocker
   Brandenburg InternetWorking
   bbiw.net