Re: [stir] PASSporT question

Piotr Gregor <piotr@signalwire.com> Tue, 28 April 2020 20:45 UTC

Return-Path: <piotr@signalwire.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15AC43A0CF0 for <stir@ietfa.amsl.com>; Tue, 28 Apr 2020 13:45:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=signalwire.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DqPYMNxIMzsO for <stir@ietfa.amsl.com>; Tue, 28 Apr 2020 13:45:40 -0700 (PDT)
Received: from mail-oo1-xc35.google.com (mail-oo1-xc35.google.com [IPv6:2607:f8b0:4864:20::c35]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 907433A0CEE for <stir@ietf.org>; Tue, 28 Apr 2020 13:45:40 -0700 (PDT)
Received: by mail-oo1-xc35.google.com with SMTP id q204so5026059ooq.1 for <stir@ietf.org>; Tue, 28 Apr 2020 13:45:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=signalwire.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=qp+ykPcpJLN/LPaUMO06hNtMXjInGfB0CtkZpts7Ogg=; b=fOUIRTbFgfY8VQ10M8YlTp8lzo8XOyLvY/IH0lShDNbsE1DoGTE7TujHkbtarCMDCU deCZuT9m8SGAOISqFWHWvNHkekOyFU6xUDXQ6UuBN+nSB5eMWO1iPD5wgklgd8DZt60v C0MRapixCwiKj2Nx0bM+N9cfwMikz1iBmaRIk=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=qp+ykPcpJLN/LPaUMO06hNtMXjInGfB0CtkZpts7Ogg=; b=ri7hrxm8EpV9zrCPi0/ErWfnM/nTEJvWSrd1DluXYLyV5kDacvVPSXBJtncsaJoVhx pLzDlknl1qLFytgvy7BLXQoi5GXrNybehSPwXDXPeG0ZL4rjlvEc077Pmb0cGXgtcfKH txHgwY1MpMGV+lO2L6jccr4VQcPcZNzD0pWipqY5zuWlbQQGVbZQ4Y2+q2VbPdVejO+7 ZAnP4QQpxmEnlUJZICYqDMBQK+LXkf6jxUSbqD9nTY4/hnBNTHV1uuf6Mvpd1nOJivns Bha5iZGXqz6xVUezHVr7nNlvIdTRTgTWNJOuZYitTwgT2xPdEw1WbZo5hWcwpOsPysRy MgpA==
X-Gm-Message-State: AGi0PuZp0Zg72aKurTAsR7qWu5IRFQu3q/w7biQ0s+qO+/rN+WL/0gi5 +jBonRKbsHbLTZWhDyjKSn6aF0dGBhRoSzY1QiFvo1sTENE=
X-Google-Smtp-Source: APiQypKC+08PnTt/E9avR6trW0CdK43trUqDnSnTiVy77RSvdf+UhGLmd8/wXpUIGn4CHkjWs0LGwIGmIa6FrdR9o0o=
X-Received: by 2002:a4a:2fd3:: with SMTP id p202mr24704480oop.33.1588106739664; Tue, 28 Apr 2020 13:45:39 -0700 (PDT)
MIME-Version: 1.0
References: <62e762b6-4a1e-7d16-ced3-09ae785a30cc@mtcc.com>
In-Reply-To: <62e762b6-4a1e-7d16-ced3-09ae785a30cc@mtcc.com>
From: Piotr Gregor <piotr@signalwire.com>
Date: Tue, 28 Apr 2020 21:45:03 +0100
Message-ID: <CA+LnPOdq8W-6JOjHkmavgbt0dn_Pv2TZMgCd9gtv8nif+fu6Ow@mail.gmail.com>
To: Michael Thomas <mike@mtcc.com>
Cc: stir@ietf.org
Content-Type: multipart/alternative; boundary="00000000000015618805a45feae3"
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/wxvpM_AwMhlB3p3HF6tqH9PM8kc>
Subject: Re: [stir] PASSporT question
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Apr 2020 20:45:42 -0000

Hi Michael,

No, "personal" in PASSporT simply comes from the fact that PASSporT is
created to assert identity of the originator, and thus it's got the name of
"personal" identity,
but it simply means asserting some identity, and it is of course the origin
of the call, calling number.

RFC 8225:

> The Personal Assertion Token, PASSporT, is
> cryptographically signed to protect the integrity of the identity of the
> originator (...)


There is ofcourse many ways the call can be originated, it can be made by a
person (and here PASSporT indeed would be "personal assertion token")
but it can be initiated by a software, without any human being involved -
STIR-Shaken could be used just as well in this case with it's PASSporT to
sign the call,
important bit is only that it asserts the origin of the call.

BTW: It is my first post on this list so may I introduce myself. My name is
Piotr Gregor and I am working with SignalWire on STIR-Shaken. Welcome!

cheers,
Piotr