Re: [tram] Fwd: New Version Notification for draft-williams-tram-ufrag-permission-00.txt

"Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com> Thu, 15 October 2015 02:39 UTC

Return-Path: <tireddy@cisco.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DD3871B2F24 for <tram@ietfa.amsl.com>; Wed, 14 Oct 2015 19:39:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level:
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tpo9lZuEdkdD for <tram@ietfa.amsl.com>; Wed, 14 Oct 2015 19:39:54 -0700 (PDT)
Received: from rcdn-iport-9.cisco.com (rcdn-iport-9.cisco.com [173.37.86.80]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 52F861B2F23 for <tram@ietf.org>; Wed, 14 Oct 2015 19:39:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3015; q=dns/txt; s=iport; t=1444876794; x=1446086394; h=from:to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version; bh=vhlG9IEwLy4TTmnWubWL+XBIc8Coe0oHp3DqcG0hwfM=; b=VY2hWNKXlxy1I5x193riHaanpvKbv/sxklTO9Q77TPxYR+jM2xn4MsW2 L32RYWQk1VQ7YX2h5hzSX2vOSwP9zV/F3gV019JfN985PRcLvN7oByIRp 1UmEM46ekrYoyJ98CKECptg1LjjlaLX10/NNHczAuA67yeQoNvLAOEUoZ U=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D/AQBmER9W/5NdJa1egyZUbga9JgENgVoXDIV5AoFBOBQBAQEBAQEBgQqEJgEBAQQBAQE3NAkOBAIBCBEDAQEBGQYJBycLFAkIAgQBEgiIJg3DHQEBAQEBAQEBAQEBAQEBAQEBAQEBAReGdoR+hEJSBhOEFQWND4kIAYUYh3uBX0iDcpIKg24BHwEBQoIRHRaBP3GFaYEGAQEB
X-IronPort-AV: E=Sophos;i="5.17,683,1437436800"; d="scan'208";a="35835490"
Received: from rcdn-core-11.cisco.com ([173.37.93.147]) by rcdn-iport-9.cisco.com with ESMTP; 15 Oct 2015 02:39:53 +0000
Received: from XCH-RCD-016.cisco.com (xch-rcd-016.cisco.com [173.37.102.26]) by rcdn-core-11.cisco.com (8.14.5/8.14.5) with ESMTP id t9F2drK5004584 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 15 Oct 2015 02:39:53 GMT
Received: from xch-rcd-017.cisco.com (173.37.102.27) by XCH-RCD-016.cisco.com (173.37.102.26) with Microsoft SMTP Server (TLS) id 15.0.1104.5; Wed, 14 Oct 2015 21:39:39 -0500
Received: from xch-rcd-017.cisco.com ([173.37.102.27]) by XCH-RCD-017.cisco.com ([173.37.102.27]) with mapi id 15.00.1104.000; Wed, 14 Oct 2015 21:39:39 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: Brandon Williams <brandon.williams@akamai.com>, "tram@ietf.org" <tram@ietf.org>
Thread-Topic: [tram] Fwd: New Version Notification for draft-williams-tram-ufrag-permission-00.txt
Thread-Index: AQHRBsN6OCadmQ7n50uWh/qIYtbSj55r018A
Date: Thu, 15 Oct 2015 02:39:39 +0000
Message-ID: <f96d4d9f87e142ef8d7cbb8a6d011dd0@XCH-RCD-017.cisco.com>
References: <20151014204935.16722.52620.idtracker@ietfa.amsl.com> <561EC1B5.3000206@akamai.com>
In-Reply-To: <561EC1B5.3000206@akamai.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.65.45.104]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/UtPcr5-W1wqBER3CRy0pCCW0zfY>
Subject: Re: [tram] Fwd: New Version Notification for draft-williams-tram-ufrag-permission-00.txt
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 15 Oct 2015 02:39:56 -0000

To handle DDOS attack of spoofed ICE requests, did you consider the option of signaling the endpoint's short-term password to TURN server so as to block those ICE requests ?
draft-jennings-behave-rtcweb-firewall-01 and this draft are both discussing STUN inspection on firewalls and TURN servers but in different ways to solve different problems.
 
-Tiru

> -----Original Message-----
> From: tram [mailto:tram-bounces@ietf.org] On Behalf Of Brandon Williams
> Sent: Thursday, October 15, 2015 2:27 AM
> To: tram@ietf.org
> Subject: [tram] Fwd: New Version Notification for draft-williams-tram-ufrag-
> permission-00.txt
> 
> I just posted the below referenced draft. It's focused on improving the speed
> of relayed ICE connectivity checks by defining a new type of permission that
> makes use of the offerer's ICE ufrag.
> 
> We will appreciate your comments.
> 
> Thanks,
> --Brandon
> 
> 
> -------- Forwarded Message --------
> Subject: New Version Notification for
> draft-williams-tram-ufrag-permission-00.txt
> Date: Wed, 14 Oct 2015 13:49:35 -0700
> From: internet-drafts@ietf.org
> To: Brandon Williams <brandon.williams@akamai.com>, Brandon Williams
> <brandon.williams@akamai.com>, Justin Uberti <justin@uberti.name>,
> Justin Uberti <justin@uberti.name>
> 
> 
> A new version of I-D, draft-williams-tram-ufrag-permission-00.txt
> has been successfully submitted by Brandon Williams and posted to the IETF
> repository.
> 
> Name:		draft-williams-tram-ufrag-permission
> Revision:	00
> Title:		Ufrag Permissions for Traversal Using Relays around NAT
> (TURN)
> Document date:	2015-10-14
> Group:		Individual Submission
> Pages:		9
> URL:
> https://www.ietf.org/internet-drafts/draft-williams-tram-ufrag-permission-
> 00.txt
> Status:
> https://datatracker.ietf.org/doc/draft-williams-tram-ufrag-permission/
> Htmlized:
> https://tools.ietf.org/html/draft-williams-tram-ufrag-permission-00
> 
> 
> Abstract:
>     When using a TURN relay, ICE connectivity checks require an explicit
>     permission or channel binding to be established for each peer address
>     to be checked.  This requires the answerer to send its candidate
>     addresses to the offerer via the rendezvous server, which can impose
>     a latency penalty when the rendezvous server is centrally located.
>     This document defines a new type of TURN permission that will allow
>     any ICE connectivity check message that contains the offerer's ufrag
>     value to be accepted on a relay address for delivery over the
>     associated TURN tunnel.
> 
> 
> 
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> The IETF Secretariat
> 
> 
> 
> _______________________________________________
> tram mailing list
> tram@ietf.org
> https://www.ietf.org/mailman/listinfo/tram