Re: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)

"Ben Campbell" <ben@nostrum.com> Wed, 23 March 2016 05:44 UTC

Return-Path: <ben@nostrum.com>
X-Original-To: straw@ietfa.amsl.com
Delivered-To: straw@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 524BE12D0C1 for <straw@ietfa.amsl.com>; Tue, 22 Mar 2016 22:44:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L_qt4Mwt-auy for <straw@ietfa.amsl.com>; Tue, 22 Mar 2016 22:44:19 -0700 (PDT)
Received: from nostrum.com (raven-v6.nostrum.com [IPv6:2001:470:d:1130::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B0A4B12D0BD for <straw@ietf.org>; Tue, 22 Mar 2016 22:44:19 -0700 (PDT)
Received: from [10.0.1.10] (cpe-70-119-203-4.tx.res.rr.com [70.119.203.4]) (authenticated bits=0) by nostrum.com (8.15.2/8.14.9) with ESMTPSA id u2N5i8ai032676 (version=TLSv1 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO); Wed, 23 Mar 2016 00:44:08 -0500 (CDT) (envelope-from ben@nostrum.com)
X-Authentication-Warning: raven.nostrum.com: Host cpe-70-119-203-4.tx.res.rr.com [70.119.203.4] claimed to be [10.0.1.10]
From: Ben Campbell <ben@nostrum.com>
To: Tirumaleswar Reddy <tireddy@cisco.com>
Date: Wed, 23 Mar 2016 00:44:08 -0500
Message-ID: <F7490450-DF0E-4B5B-84FC-88F7D7BDB6EC@nostrum.com>
In-Reply-To: <1de1a6731ca44da6b9276fbbc76c7f7a@XCH-RCD-017.cisco.com>
References: <20151201045818.23491.19134.idtracker@ietfa.amsl.com> <E63559A7-6A37-496C-AAD9-426AB697FD65@nostrum.com> <D2851411.4B35B%rmohanr@cisco.com> <DB9B999A-DAF0-440B-BDD4-445368AFFCE2@cooperw.in> <DAE78890-C8B2-42DE-BCC3-A994CB9AF668@nostrum.com> <1D498CDA-C8B6-4215-A718-7C5302B5CF2D@cooperw.in> <01E4CF3B-6C31-4A97-8155-8DC06443A7C2@nostrum.com> <A6B3CA82-DC74-48AB-80B7-EBF1462A964E@nostrum.com> <D2C25ED1.4E4DA%rmohanr@cisco.com> <23C852C2-1B96-4739-91ED-8B4C0FF97279@cooperw.in> <D314CB23.5573B%rmohanr@cisco.com> <9F61F2A3-355F-4053-B110-3899CF337A4E@nostrum.com> <D316D3F7.55B12%rmohanr@cisco.com> <1de1a6731ca44da6b9276fbbc76c7f7a@XCH-RCD-017.cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"
X-Mailer: MailMate (1.9.4r5234)
Archived-At: <http://mailarchive.ietf.org/arch/msg/straw/HdcPiywwropQKypkA_-2ELtokJE>
Cc: Ram Mohan R <rmohanr@cisco.com>, Alissa Cooper <alissa@cooperw.in>, "straw@ietf.org" <straw@ietf.org>, "christer.holmberg@ericsson.com" <christer.holmberg@ericsson.com>
Subject: Re: [straw] Alissa Cooper's Discuss on draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)
X-BeenThere: straw@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Sip Traversal Required for Applications to Work \(STRAW\) working group discussion list" <straw.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/straw>, <mailto:straw-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/straw/>
List-Post: <mailto:straw@ietf.org>
List-Help: <mailto:straw-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/straw>, <mailto:straw-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Mar 2016 05:44:21 -0000

On 22 Mar 2016, at 23:00, Tirumaleswar Reddy (tireddy) wrote:

>> -----Original Message-----
>> From: straw [mailto:straw-bounces@ietf.org] On Behalf Of Ram Mohan R
>> (rmohanr)
>> Sent: Tuesday, March 22, 2016 10:46 AM
>> To: Ben Campbell
>> Cc: Alissa Cooper; straw@ietf.org; christer.holmberg@ericsson.com
>> Subject: Re: [straw] Alissa Cooper's Discuss on 
>> draft-ietf-straw-b2bua-dtls-
>> srtp-09: (with DISCUSS and COMMENT)
>>
>> Hi Ben,
>>
>> -----Original Message-----
>> From: Ben Campbell <ben@nostrum.com>
>> Date: Tuesday, 22 March 2016 at 12:08 AM
>> To: Cisco Employee <rmohanr@cisco.com>
>> Cc: Alissa Cooper <alissa@cooperw.in>, "straw@ietf.org" 
>> <straw@ietf.org>,
>> "christer.holmberg@ericsson.com" <christer.holmberg@ericsson.com>
>> Subject: Re: [straw] Alissa Cooper's Discuss on
>> draft-ietf-straw-b2bua-dtls-srtp-09: (with DISCUSS and COMMENT)
>>
>>>> NEW:
>>>> B2BUAs may be deployed for address hiding or media latching 
>>>> [RFC7362],
>>>> although TURN is more often used for this purpose and media 
>>>> latching
>>>> is not recommended due to its security properties. Such B2BUAs are
>>>> able to perform their functions without requiring termination of
>>>> DTLS-SRTP sessions i.e.
>>>> these B2BUAs need not act as DTLS proxy and decrypt the RTP 
>>>> payload.
>>>
>>> I think the statement that TURN is more often used for media 
>>> latching
>>> is at least somewhat aspirational. But I'm okay with that aspiration
>>> :-)
>>
>> :) Agree. There are more B2BUAs out there in field doing latching 
>> than people
>> using TURN.
>> But I think there is no harm in saying this way.
>
> How about the following text ?
> B2BUAs may be deployed for address hiding or media latching [RFC7362], 
> although endpoints can use ICE, only advertise the relayed candidate 
> allocated by the TURN server for address privacy to the remote peer 
> and avoid the security threats discussed in Section 5 of [RFC7362].
>

  My preference is the language that Ram and Alissa came up with 
(aspirational or otherwise.) Aspirational or not, I think we should make 
it clear that the IETF does not recommend SBC media latching and prefers 
TURN.

Ben.