Re: [tram] Sync STUN and SIP auth

Alan Johnston <alan.b.johnston@gmail.com> Thu, 19 March 2015 14:01 UTC

Return-Path: <alan.b.johnston@gmail.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 839FE1AC3F3 for <tram@ietfa.amsl.com>; Thu, 19 Mar 2015 07:01:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id grAwF7n0Ecxh for <tram@ietfa.amsl.com>; Thu, 19 Mar 2015 07:01:30 -0700 (PDT)
Received: from mail-vc0-x233.google.com (mail-vc0-x233.google.com [IPv6:2607:f8b0:400c:c03::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DFCC91A8A63 for <tram@ietf.org>; Thu, 19 Mar 2015 07:01:29 -0700 (PDT)
Received: by mail-vc0-f179.google.com with SMTP id la4so19280014vcb.10 for <tram@ietf.org>; Thu, 19 Mar 2015 07:01:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=I5w4sQY8IChxQR4q/4VFdSws1lgEjMFfNGMK3kHyXi4=; b=v2kU/7WlFH+9LkyH4cUWGM4yXRe7K2PAK3fslAY95YhsuRifPlmCrMIQ6cFe5Rdap9 LUNiZtakIkePgrzByrUt/DVrGnSRqOjLlqStjzLGYuJFuKONz8CshGxf8v/7BkTcAeQc SX6aEFkAQQTjBhMhSrMm9GKRttJTF2G0JURY2YElFNNN/qAHlcZEi9HfzS2n8g/INkZi wylZWYHZ0Lar+G2PC3OpOgl7GZXxgICt4fIqkCcvEqzNF6QT2O3TA8z9Q9exCB57WOqA ALrLjNZvKPJ8z6AXo+Ab74pnhnZF11Hx4TBJYorSmI3xpOEY5EI1m8M2ygTmF27OiIqw 9NJQ==
MIME-Version: 1.0
X-Received: by 10.52.139.16 with SMTP id qu16mr78316152vdb.43.1426773689132; Thu, 19 Mar 2015 07:01:29 -0700 (PDT)
Received: by 10.52.121.111 with HTTP; Thu, 19 Mar 2015 07:01:29 -0700 (PDT)
In-Reply-To: <550AD53A.6090007@acm.org>
References: <CAKhHsXEcvr8W7qk3Czx1E+DqqVOk_8V_+Bn3ZB5yjXdf=7aGJQ@mail.gmail.com> <550AAF8A.9080205@acm.org> <550AD275.1010804@jive.com> <550AD53A.6090007@acm.org>
Date: Thu, 19 Mar 2015 09:01:29 -0500
Message-ID: <CAKhHsXHaCin-+uk1jVzt7GU7xdSxN+ZsBpvQ1RTW+mxdtSmqcA@mail.gmail.com>
From: Alan Johnston <alan.b.johnston@gmail.com>
To: Marc Petit-Huguenin <petithug@acm.org>
Content-Type: multipart/alternative; boundary="bcaec52c6389ea70520511a4a223"
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/WHWcSnOUHuy48uFFG2mY1grQ8v4>
Cc: Simon Perreault <sperreault@jive.com>, "tram@ietf.org" <tram@ietf.org>, Rifaat Shekh-Yusef <rifaat.ietf@gmail.com>
Subject: Re: [tram] Sync STUN and SIP auth
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Mar 2015 14:01:32 -0000

Marc & Simon,

Rifaat and many other SIPCORE folks will be in Dallas next week, so we
should definitely meet up and figure out a solution.

- Alan -


On Thu, Mar 19, 2015 at 8:55 AM, Marc Petit-Huguenin <petithug@acm.org>
wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> On 03/19/2015 07:43 AM, Simon Perreault wrote:
> > Le 2015-03-19 07:14, Marc Petit-Huguenin a écrit :
> >>> Does the use of salted SHA256 for passwords match up with what is
> planned
> >>> for SIP?  See:
> >>>
> >>>     https://tools.ietf.org/html/draft-yusef-sipcore-digest-scheme
> >>>
> >>> Does H(A1) match up?  Also, I'm not aware if this draft is moving
> forward:
> >>>
> >>>     https://tools.ietf.org/html/draft-veltri-sip-alt-auth
> >> It is not, which is sad because I find it better than
> draft-yusef-sipcore-digest-scheme.  It also fits better with STUN where the
> hash algorithm (SHA-1 and now SHA256) has been split off the password hash
> algorithm (MD5) from the beginning.  draft-yusef-sipcore-digest-scheme does
> not even talk about the password algorithm, continuing the (I think) rather
> bad idea of linking the two together.
> >
> > What you're saying makes sense, yet does not bring us closer to syncing
> > STUN and SIP auth. I don't know if it is a possible goal, but I feel it
> > is our duty to at least explore the possibility.
> >
> > I note that the two drafts above are not working-group drafts. It would
> > be good to have a chat with the sipcore chairs in Dallas and reach a
> > common understanding of the situation...
>
> Let's do that, but I noticed that sipcore will not have a session in
> Dallas.
>
> >
> > Simon
> >
>
>
> - --
> Marc Petit-Huguenin
> Email: marc@petit-huguenin.org
> Blog: http://blog.marc.petit-huguenin.org
> Profile: http://www.linkedin.com/in/petithug
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1
>
> iQIcBAEBCAAGBQJVCtU5AAoJECnERZXWan7EHyYP/1gnBqKC/J1zuPYg+M4Xg3qV
> tXFQwAcTv9CuF+/9j0+vkSyUluopXTPP4i9hf8Ms4PRZc6QT3ZkBqpDwkZZYuXQK
> zPyxT1o2D5XV1dnjYfZXZcN68Bf/5rR23EHYRdY1j/fMPrEJkVP7vtu3Sr3xfXA7
> m4zcdKLA4u2OmK5aeDHP24+zcRAXOJ07WW6gudKSb3MAzOyn3sL4hC56tgQdJWNO
> wEyZXhIP4VdBjGy0Cs9wNrvZsgi7AR9J3HkOGZMv9gpH5ZI3yJYBHbyn3IuGa/ig
> u+rEXwXjdvBVPEmrNyd3PURop1V9szsHg2x86wn58DbH4YmRJeqXHT8uPiug+c7A
> 59rEPxiN3ajRQaN+KVEE7Zp5iQeFpPRKz6FJtd1261eMFawE0vMApGC4oaVZuEL8
> KQIGu+trEixJG8SI29UwYq5YLOOQsDBLP+q6uV6nqYgz9G8I2d4MeTZpTHQxOoGl
> 3+8OFkUJzqiteo59PP281NW4GCwS63iuRNzGHkpdb14X9SA91MJ0EEU0tcfMbro7
> u7APmH40ID8TqzfW2WQiL4ZlxxoyAIdMT4GkE13wAkxbJWQdEDJ19yfmMX6rtqnn
> lpMKsQFmZC3fyfZ43IuzJEziGcq+QDbltqetmef1kKnoDKTIHE3TX7FldUyIo7Ap
> P2FJWLCJksSm6yKh2O/2
> =5Iz6
> -----END PGP SIGNATURE-----
>