Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)

"Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com> Wed, 15 April 2015 16:10 UTC

Return-Path: <tireddy@cisco.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E88C51B2CD8; Wed, 15 Apr 2015 09:10:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level:
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HdEj6zVgd1M6; Wed, 15 Apr 2015 09:10:04 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 97B961B2CD2; Wed, 15 Apr 2015 09:10:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=1922; q=dns/txt; s=iport; t=1429114205; x=1430323805; h=from:to:cc:subject:date:message-id: content-transfer-encoding:mime-version; bh=65G/SC1dzjTZu2pp2Wybes/AAp7LiLDJgDpwW56rjo4=; b=JpnmLV3/pUSMP62NVa3AlPTZe2j/tbsm4MZfiQkCI6JiUAY+CQ44uRXQ ly/P5ZEDPBzvSq7CsK50bRA+uBgEqOxrIDca87xVf2Pyfhln596/Slv8U 9Bbf2ayGl3ZTsbaNqAeBCzk843lXetE677N1/jBJhomFM+VpB4LOkeHLa I=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BVBQAXjS5V/4sNJK1cgwyBLgWDEMFoiEECHIEfTAEBAQEBAX6EIAEBAQQjETgKAwwGAQgOAwQBAQECAgYZBAMCBB8RFAEICQEEAQ0FCIgOAxGvHJBHDYUrAQEBAQEBAQEBAQEBAQEBAQEBAQEBF4EhigqCSIFpGjENgmIvgRYBBJEOiESQAYY7IoIzgTxvgUR/AQEB
X-IronPort-AV: E=Sophos;i="5.11,582,1422921600"; d="scan'208";a="412099753"
Received: from alln-core-6.cisco.com ([173.36.13.139]) by rcdn-iport-6.cisco.com with ESMTP; 15 Apr 2015 16:10:04 +0000
Received: from xhc-rcd-x06.cisco.com (xhc-rcd-x06.cisco.com [173.37.183.80]) by alln-core-6.cisco.com (8.14.5/8.14.5) with ESMTP id t3FGA3bM018652 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 15 Apr 2015 16:10:03 GMT
Received: from xmb-rcd-x10.cisco.com ([169.254.15.220]) by xhc-rcd-x06.cisco.com ([173.37.183.80]) with mapi id 14.03.0195.001; Wed, 15 Apr 2015 11:10:03 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: Oleg Moskalenko <mom040267@gmail.com>, Martin Thomson <martin.thomson@gmail.com>
Thread-Topic: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)
Thread-Index: AdB3lrTivwSQTgMcQK2cznUvsf1wvA==
Date: Wed, 15 Apr 2015 16:10:03 +0000
Message-ID: <913383AAA69FF945B8F946018B75898A4120E588@xmb-rcd-x10.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.65.73.110]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/HHqSknmH7Ft5zQscVbDCFESEUmQ>
Cc: "tram-chairs@ietf.org" <tram-chairs@ietf.org>, "tram@ietf.org" <tram@ietf.org>, Brandon Williams <brandon.williams@akamai.com>, "rlb@ipv.sx" <rlb@ipv.sx>, "Salz, Rich" <rsalz@akamai.com>, "Stephen Farrell (stephen.farrell@cs.tcd.ie)" <stephen.farrell@cs.tcd.ie>
Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Apr 2015 16:10:06 -0000

> -----Original Message-----
> From: Oleg Moskalenko [mailto:mom040267@gmail.com]
> Sent: Wednesday, April 15, 2015 2:50 AM
> To: Martin Thomson
> Cc: Tirumaleswar Reddy (tireddy); tram-chairs@ietf.org; tram@ietf.org;
> Brandon Williams; rlb@ipv.sx; Salz, Rich; Stephen Farrell
> (stephen.farrell@cs.tcd.ie)
> Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-
> party-authz-13: (with DISCUSS and COMMENT)
> 
> On Tue, Apr 14, 2015 at 1:18 PM, Martin Thomson
> <martin.thomson@gmail.com> wrote:
> > On 14 April 2015 at 12:53, Oleg Moskalenko <mom040267@gmail.com>
> wrote:
> >> You can set the server name to
> > "Martin Thomson" and it will be perfectly OK.
> >
> > OK, you still haven't explained why such a field needs to be defined
> > in an RFC.  Ideally, the draft should contain that explanation.
> 
> The draft fully explains why we need that field for the sake of
> encryption/authorization. I do not believe that it can be explained clearer.

Yes, it's explained in section 6.2

<snip>
   The associated data (A) MUST be the STUN server name.  This ensures
   that the client does not use the same token to gain illegal access to
   other STUN servers provided by the same administrative domain i.e.,
   when multiple STUN servers in a single administrative domain share
   the same symmetric key with an authorization server.
</snip>