Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)

Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com> Wed, 22 April 2015 16:56 UTC

Return-Path: <spencerdawkins.ietf@gmail.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E18A31B3718; Wed, 22 Apr 2015 09:56:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RBCMLCg0Viel; Wed, 22 Apr 2015 09:56:00 -0700 (PDT)
Received: from mail-la0-x231.google.com (mail-la0-x231.google.com [IPv6:2a00:1450:4010:c03::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2F75A1B3806; Wed, 22 Apr 2015 09:55:44 -0700 (PDT)
Received: by laat2 with SMTP id t2so179664961laa.1; Wed, 22 Apr 2015 09:55:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=+0dTnxyHW2vJ8CRfatkFlTLpGjjk8AiikQUIEL9leDs=; b=MtqY63sqWgfEU2X0RZegNrzLaynA5GqP71kaINKOZQ8rWhIiO1+PeWpMHktoSST1iH B9Zn3Nf9E9U/92hnQLOUQEXgWsy33NAKPth3G8rC1A6bNybzyLQ5I2nx3z0hMvuUVTXC KbfT5KXHFNO1Py/zIo5z4jBkm1nIrsq4i+KnNqswUyr+TtGqZujoSiX0KTdEIyzfAVRD 8suuoWBE2FrW93SxuMN9SbsmCqBYDtq/gRhCwIhRHAqy9kn+kfzbODTd2PQHh4MlR3p2 /gwzYTjUupqj2iZZswBfZpHhBaUhAWJsTHgQWjQlklQYBEhYMIDP+FFjjnqrh3lpmaGn XHAw==
MIME-Version: 1.0
X-Received: by 10.152.203.162 with SMTP id kr2mr25566863lac.68.1429721742684; Wed, 22 Apr 2015 09:55:42 -0700 (PDT)
Received: by 10.152.129.3 with HTTP; Wed, 22 Apr 2015 09:55:42 -0700 (PDT)
In-Reply-To: <30eaf35d875745128662076920f72ae8@usma1ex-dag1mb2.msg.corp.akamai.com>
References: <913383AAA69FF945B8F946018B75898A4120E0BD@xmb-rcd-x10.cisco.com> <55369856.7050203@akamai.com> <913383AAA69FF945B8F946018B75898A41214674@xmb-rcd-x10.cisco.com> <a20208ec333b45d29956e5bda4a61686@usma1ex-dag1mb2.msg.corp.akamai.com> <913383AAA69FF945B8F946018B75898A4121478B@xmb-rcd-x10.cisco.com> <30eaf35d875745128662076920f72ae8@usma1ex-dag1mb2.msg.corp.akamai.com>
Date: Wed, 22 Apr 2015 11:55:42 -0500
Message-ID: <CAKKJt-eTFgXNQUF_SvSwyJmXuxmBH0ejqz-T7OZepOBPn4oj0A@mail.gmail.com>
From: Spencer Dawkins at IETF <spencerdawkins.ietf@gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Content-Type: multipart/alternative; boundary="001a1134632699b9640514530894"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/OVClnS6C8ApoM-kFIPBhK8axKdM>
Cc: "tram-chairs@ietf.org" <tram-chairs@ietf.org>, "tram@ietf.org" <tram@ietf.org>, "rlb@ipv.sx" <rlb@ipv.sx>, "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>, "Williams, Brandon" <bowill@akamai.com>, Martin Thomson <martin.thomson@gmail.com>, "Stephen Farrell (stephen.farrell@cs.tcd.ie)" <stephen.farrell@cs.tcd.ie>
Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-13: (with DISCUSS and COMMENT)
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Apr 2015 16:56:02 -0000

Hi, Rich,

On Tue, Apr 21, 2015 at 11:14 PM, Salz, Rich <rsalz@akamai.com> wrote:

> > https://tools.ietf.org/html/rfc6194#section-3 discusses problems with
> SHA1.
> > Is it safe to derive key using SHA1 ?
>
> Those concerns do not apply here.  Yes, absolutely safe.
>

I saw that Tiru has already made that change in a later mail in this
thread, and that's fine. This is just for my education.

I'm not in my native element here, so I'm not questioning your statement,
but could you explain to me (I'm thinking like a sentence, not like a
thesis) on why those concerns don't apply?

Another AD could reasonably ask during balloting or the telechat, because
we all know to twitch when SHA-1 is mentioned, and I'd like to be able to
provide more than a shrug :-)


> --
> Senior Architect, Akamai Technologies
> IM: richsalz@jabber.at Twitter: RichSalz
>
> _______________________________________________
> tram mailing list
> tram@ietf.org
> https://www.ietf.org/mailman/listinfo/tram
>