Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)

Oleg Moskalenko <mom040267@gmail.com> Tue, 14 April 2015 06:11 UTC

Return-Path: <mom040267@gmail.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6716E1B3413; Mon, 13 Apr 2015 23:11:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.75
X-Spam-Level:
X-Spam-Status: No, score=-1.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Mj7NvGk6bCJf; Mon, 13 Apr 2015 23:11:54 -0700 (PDT)
Received: from mail-wg0-x230.google.com (mail-wg0-x230.google.com [IPv6:2a00:1450:400c:c00::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 10A431B3412; Mon, 13 Apr 2015 23:11:54 -0700 (PDT)
Received: by wgso17 with SMTP id o17so36423wgs.1; Mon, 13 Apr 2015 23:11:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:content-transfer-encoding; bh=7apUoGYf4DiBBW/M7UoDrnUiw5N0UnZcgm6TMILVEHs=; b=Y7nf2GtZrXXkmpUlLuWbROhLIWDjLnTRMvZjcEgjj5ei30pPS7NkRqPVgxMzLEWjFV q0OjOMJyP/TWXO6HsBx8EcrTBX1cg/bE2MpA4hp2AsFOZyFeNcNennA5y2ciydpbpACU YZvz2nwHx9EqwM9afw594aPU3hUSdT5wsB/Ytt/axMPjigWLo3mbuACmharqYyfY7UN2 zDtTdWZmDrbKg4OTBRxrXvUSgtxpiByehcHQxCU3DzoUZdF3By+WjY9w4VuMzBC7OLvU dWLA8tCASkXI5WEDcwrfenmDBDmVFcRAsVYWAcUzAo1tcSHnSjuWb5Jfj9icaPoZmbAV 4Zng==
MIME-Version: 1.0
X-Received: by 10.180.80.105 with SMTP id q9mr9856332wix.52.1428991912858; Mon, 13 Apr 2015 23:11:52 -0700 (PDT)
Received: by 10.194.190.7 with HTTP; Mon, 13 Apr 2015 23:11:52 -0700 (PDT)
In-Reply-To: <913383AAA69FF945B8F946018B75898A4120D628@xmb-rcd-x10.cisco.com>
References: <20150410193813.20376.40907.idtracker@ietfa.amsl.com> <55282B4E.4000409@akamai.com> <913383AAA69FF945B8F946018B75898A411FFC5F@xmb-rcd-x10.cisco.com> <CABkgnnUyHTd83LWM0Lp0xOJnVp3Gt6KvrbuGkraejP7kwEJf7w@mail.gmail.com> <CALDtMrLO-kqM4LTOgKJq90swE52k0draQ110t5Q8GVfUwPFpUQ@mail.gmail.com> <913383AAA69FF945B8F946018B75898A4120D628@xmb-rcd-x10.cisco.com>
Date: Mon, 13 Apr 2015 23:11:52 -0700
Message-ID: <CALDtMrL4gMPNpzJznCT8sLbgSrsQtAJuXmikwyNjnxDPpWFW-A@mail.gmail.com>
From: Oleg Moskalenko <mom040267@gmail.com>
To: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/8Sm1D55v6P4xqFdtr_9V9PzBSJk>
Cc: "tram-chairs@ietf.org" <tram-chairs@ietf.org>, "tram@ietf.org" <tram@ietf.org>, Brandon Williams <brandon.williams@akamai.com>, "rlb@ipv.sx" <rlb@ipv.sx>, "Salz, Rich" <rsalz@akamai.com>, Martin Thomson <martin.thomson@gmail.com>, "Stephen Farrell (stephen.farrell@cs.tcd.ie)" <stephen.farrell@cs.tcd.ie>
Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Apr 2015 06:11:55 -0000

On Mon, Apr 13, 2015 at 11:02 PM, Tirumaleswar Reddy (tireddy)
<tireddy@cisco.com> wrote:
>>
>>
>> I believe that extra token information is a very very bad idea - it kills the
>> whole interoperability thing in the draft. If we are adding "extra"
>> information to the token, we can as well just kill the draft and tell the STUN
>> server developers "do whatever you want, secure the stuff somehow, we do
>> not care".
>
> It was discussed in the WG and decision was not to carry any extra token information so as to keep the token size small. In future an out-of-band communication mechanism b/w STUN and authorization server to exchange the token related metadata can be defined similar to the OAuth 2.0 Token Introspection method defined in https://tools.ietf.org/html/draft-ietf-oauth-introspection-07.
>

if that extra information is formal and well-defined, then that's
fine. I was against free-formated extra fields.

Thanks
Oleg