Re: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)

"Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com> Wed, 23 March 2016 08:15 UTC

Return-Path: <tireddy@cisco.com>
X-Original-To: straw@ietfa.amsl.com
Delivered-To: straw@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D9D3F12D708 for <straw@ietfa.amsl.com>; Wed, 23 Mar 2016 01:15:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.522
X-Spam-Level:
X-Spam-Status: No, score=-14.522 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XG5FeaWdbe-W for <straw@ietfa.amsl.com>; Wed, 23 Mar 2016 01:15:15 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 12D2312D691 for <straw@ietf.org>; Wed, 23 Mar 2016 01:15:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2976; q=dns/txt; s=iport; t=1458720915; x=1459930515; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=jNT3kRJ/Y19lmJEeIdmZA01F6ctxuHCqsuBaRriBeXI=; b=asElakfor/tcBIa/cLp3wTx5q1xj8w5HLL1FDjsS3twkBgA4jTAn1Z3f egLjOY1e44jBpeDere6rdKBgoL2YcB7/dXBPmuFYfTrVvrP7sP9mKIbWu cfHxCWvr1nEa11adDCiqZa49Fr0wsgtrfF72t/nclzux+PebeLIyFlpId k=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D9AQAMUPJW/4kNJK1egzSBTQa4U4IPAQ2BcIYNAoE/OBQBAQEBAQEBZCeEQQEBAQMBOj8MBAIBCBEDAQEBAR4FBAcyFAkIAgQOBQiIFwjAXwEBAQEBAQEBAQEBAQEBAQEBAQEBARWGHoREhCSFbgWXWQGNfI8RjwYBHgEBQoIwgTVqiQ1+AQEB
X-IronPort-AV: E=Sophos;i="5.24,381,1454976000"; d="scan'208";a="85742198"
Received: from alln-core-4.cisco.com ([173.36.13.137]) by rcdn-iport-6.cisco.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 23 Mar 2016 08:15:14 +0000
Received: from XCH-ALN-020.cisco.com (xch-aln-020.cisco.com [173.36.7.30]) by alln-core-4.cisco.com (8.14.5/8.14.5) with ESMTP id u2N8FE8T025738 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Wed, 23 Mar 2016 08:15:14 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-ALN-020.cisco.com (173.36.7.30) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Wed, 23 Mar 2016 03:15:13 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1104.009; Wed, 23 Mar 2016 03:15:13 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: Ben Campbell <ben@nostrum.com>
Thread-Topic: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)
Thread-Index: AQHRMr+3OsGMVtPT80yeJvcykXh0sJ78ORMAgAULK4CAYGGggIAB0KOAgAG5fQCAALIuAIABFVDggACE3wD//8uFYA==
Date: Wed, 23 Mar 2016 08:15:13 +0000
Message-ID: <77d10995fb2f460e817c18eb630e3a77@XCH-RCD-017.cisco.com>
References: <20151201045818.23491.19134.idtracker@ietfa.amsl.com> <E63559A7-6A37-496C-AAD9-426AB697FD65@nostrum.com> <D2851411.4B35B%rmohanr@cisco.com> <DB9B999A-DAF0-440B-BDD4-445368AFFCE2@cooperw.in> <DAE78890-C8B2-42DE-BCC3-A994CB9AF668@nostrum.com> <1D498CDA-C8B6-4215-A718-7C5302B5CF2D@cooperw.in> <01E4CF3B-6C31-4A97-8155-8DC06443A7C2@nostrum.com> <A6B3CA82-DC74-48AB-80B7-EBF1462A964E@nostrum.com> <D2C25ED1.4E4DA%rmohanr@cisco.com> <23C852C2-1B96-4739-91ED-8B4C0FF97279@cooperw.in> <D314CB23.5573B%rmohanr@cisco.com> <9F61F2A3-355F-4053-B110-3899CF337A4E@nostrum.com> <D316D3F7.55B12%rmohanr@cisco.com> <1de1a6731ca44da6b9276fbbc76c7f7a@XCH-RCD-017.cisco.com> <F7490450-DF0E-4B5B-84FC-88F7D7BDB6EC@nostrum.com>
In-Reply-To: <F7490450-DF0E-4B5B-84FC-88F7D7BDB6EC@nostrum.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.86.149]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/straw/6d2Ft1cnoIJ0vq0k9NGa36W-gLU>
Cc: "Ram Mohan R (rmohanr)" <rmohanr@cisco.com>, Alissa Cooper <alissa@cooperw.in>, "straw@ietf.org" <straw@ietf.org>, "christer.holmberg@ericsson.com" <christer.holmberg@ericsson.com>
Subject: Re: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)
X-BeenThere: straw@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Sip Traversal Required for Applications to Work \(STRAW\) working group discussion list" <straw.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/straw>, <mailto:straw-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/straw/>
List-Post: <mailto:straw@ietf.org>
List-Help: <mailto:straw-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/straw>, <mailto:straw-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Mar 2016 08:15:17 -0000

> -----Original Message-----
> From: Ben Campbell [mailto:ben@nostrum.com]
> Sent: Wednesday, March 23, 2016 11:14 AM
> To: Tirumaleswar Reddy (tireddy)
> Cc: Ram Mohan R (rmohanr); Alissa Cooper; straw@ietf.org;
> christer.holmberg@ericsson.com
> Subject: Re: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-
> srtp-09: (with DISCUSS and COMMENT)
> 
> On 22 Mar 2016, at 23:00, Tirumaleswar Reddy (tireddy) wrote:
> 
> >> -----Original Message-----
> >> From: straw [mailto:straw-bounces@ietf.org] On Behalf Of Ram Mohan R
> >> (rmohanr)
> >> Sent: Tuesday, March 22, 2016 10:46 AM
> >> To: Ben Campbell
> >> Cc: Alissa Cooper; straw@ietf.org; christer.holmberg@ericsson.com
> >> Subject: Re: [straw] Alissa Cooper's Discuss on
> >> draft-ietf-straw-b2bua-dtls-
> >> srtp-09: (with DISCUSS and COMMENT)
> >>
> >> Hi Ben,
> >>
> >> -----Original Message-----
> >> From: Ben Campbell <ben@nostrum.com>
> >> Date: Tuesday, 22 March 2016 at 12:08 AM
> >> To: Cisco Employee <rmohanr@cisco.com>
> >> Cc: Alissa Cooper <alissa@cooperw.in>, "straw@ietf.org"
> >> <straw@ietf.org>,
> >> "christer.holmberg@ericsson.com" <christer.holmberg@ericsson.com>
> >> Subject: Re: [straw] Alissa Cooper's Discuss on
> >> draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)
> >>
> >>>> NEW:
> >>>> B2BUAs may be deployed for address hiding or media latching
> >>>> [RFC7362], although TURN is more often used for this purpose and
> >>>> media latching is not recommended due to its security properties.
> >>>> Such B2BUAs are able to perform their functions without requiring
> >>>> termination of DTLS-SRTP sessions i.e.
> >>>> these B2BUAs need not act as DTLS proxy and decrypt the RTP
> >>>> payload.
> >>>
> >>> I think the statement that TURN is more often used for media
> >>> latching is at least somewhat aspirational. But I'm okay with that
> >>> aspiration
> >>> :-)
> >>
> >> :) Agree. There are more B2BUAs out there in field doing latching
> >> than people using TURN.
> >> But I think there is no harm in saying this way.
> >
> > How about the following text ?
> > B2BUAs may be deployed for address hiding or media latching [RFC7362],
> > although endpoints can use ICE, only advertise the relayed candidate
> > allocated by the TURN server for address privacy to the remote peer
> > and avoid the security threats discussed in Section 5 of [RFC7362].
> >
> 
>   My preference is the language that Ram and Alissa came up with
> (aspirational or otherwise.) Aspirational or not, I think we should make it
> clear that the IETF does not recommend SBC media latching and prefers
> TURN.

Got it, but TURN has to be used with ICE.
NEW: 
B2BUAs may be deployed for address hiding or media latching [RFC7362], although TURN [RFC5766] with ICE [RFC5245] is recommended for this purpose and media latching is not recommended due to its security properties.

> 
> Ben.