Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-15: (with DISCUSS and COMMENT)

"Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com> Fri, 01 May 2015 04:43 UTC

Return-Path: <tireddy@cisco.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 62FC21B3038; Thu, 30 Apr 2015 21:43:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.511
X-Spam-Level:
X-Spam-Status: No, score=-14.511 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vsaCgoTuSV_t; Thu, 30 Apr 2015 21:43:19 -0700 (PDT)
Received: from rcdn-iport-6.cisco.com (rcdn-iport-6.cisco.com [173.37.86.77]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 968681B3037; Thu, 30 Apr 2015 21:43:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2296; q=dns/txt; s=iport; t=1430455399; x=1431664999; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=cWd5gdIe4zn7Mhhqz0oFvSmBmbpa6tkFuTHEcaPQ90Q=; b=QpncfeqDmuABIRYa2jwz4jr2ICog7com+ncDbtW3RbtTbusp8aYo43pM euVvVcpAqVGTYOBQADRnF/NE/6a8sftKM71uXiAmsK9H6lNs2eLSPIHfg BfegLWnRHo3JhxrJdG15b+qaT6sxBpce0p6ozvSMYPurjVPvr0zeDTYvz c=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0AUBQCyA0NV/5pdJa1cgwxTXAWDGMFTgkOGBAIcgTxMAQEBAQEBgQuEIAEBAQQjEUUMBAIBCBEEAQEBAgIGGQQDAgICMBQBCAgCBAENBQgBiCINs3qTPwEBAQEBAQEBAQEBAQEBAQEBAQEBAReBIYoXhDMBAQUaFhsHBoJiL4EWBZFvi22RCoNQI2CBBVOBPG8BgQo5gQEBAQE
X-IronPort-AV: E=Sophos;i="5.13,348,1427760000"; d="scan'208";a="416245713"
Received: from rcdn-core-3.cisco.com ([173.37.93.154]) by rcdn-iport-6.cisco.com with ESMTP; 01 May 2015 04:43:18 +0000
Received: from xhc-rcd-x13.cisco.com (xhc-rcd-x13.cisco.com [173.37.183.87]) by rcdn-core-3.cisco.com (8.14.5/8.14.5) with ESMTP id t414hHL1002877 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 1 May 2015 04:43:17 GMT
Received: from xmb-rcd-x10.cisco.com ([169.254.15.218]) by xhc-rcd-x13.cisco.com ([173.37.183.87]) with mapi id 14.03.0195.001; Thu, 30 Apr 2015 23:43:17 -0500
From: "Tirumaleswar Reddy (tireddy)" <tireddy@cisco.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, Oleg Moskalenko <mom040267@gmail.com>
Thread-Topic: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-15: (with DISCUSS and COMMENT)
Thread-Index: AQHQgfljn3eNkKZMFkCfMqDWMLcdXp1kslWAgAAYOYCAAEf1gIAAcQwAgAAJ/YCAAAOlAIAA8P+Q
Date: Fri, 01 May 2015 04:43:17 +0000
Message-ID: <913383AAA69FF945B8F946018B75898A4782328F@xmb-rcd-x10.cisco.com>
References: <20150428212204.9453.5930.idtracker@ietfa.amsl.com> <D1667313.5436C%praspati@cisco.com> <554142C5.6030505@cs.tcd.ie> <CALDtMrJFBJKL-chgCF48N2vP9uM3s07zST2kLT_yUrXRFiJoJg@mail.gmail.com> <5541DDF6.7000205@cs.tcd.ie> <CALDtMrLZLBLS2MH1QYKx9BraJvdgGqtr67fCNDeS9jUX_GV5Qg@mail.gmail.com> <5541E966.80602@cs.tcd.ie>
In-Reply-To: <5541E966.80602@cs.tcd.ie>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.65.74.86]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/kY8IHXtLBymlSh9EiWS9JyOfaN8>
X-Mailman-Approved-At: Sat, 02 May 2015 06:29:25 -0700
Cc: "Prashanth Patil (praspati)" <praspati@cisco.com>, "tram-chairs@ietf.org" <tram-chairs@ietf.org>, "tram@ietf.org" <tram@ietf.org>, "draft-ietf-tram-turn-third-party-authz@ietf.org" <draft-ietf-tram-turn-third-party-authz@ietf.org>, "gonzalo.camarillo@ericsson.com" <gonzalo.camarillo@ericsson.com>, "draft-ietf-tram-turn-third-party-authz.ad@ietf.org" <draft-ietf-tram-turn-third-party-authz.ad@ietf.org>, The IESG <iesg@ietf.org>, "draft-ietf-tram-turn-third-party-authz.shepherd@ietf.org" <draft-ietf-tram-turn-third-party-authz.shepherd@ietf.org>
Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-party-authz-15: (with DISCUSS and COMMENT)
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 May 2015 04:43:20 -0000

> -----Original Message-----
> From: Stephen Farrell [mailto:stephen.farrell@cs.tcd.ie]
> Sent: Thursday, April 30, 2015 2:06 PM
> To: Oleg Moskalenko
> Cc: Prashanth Patil (praspati); The IESG; tram-chairs@ietf.org; tram@ietf.org;
> draft-ietf-tram-turn-third-party-authz@ietf.org;
> gonzalo.camarillo@ericsson.com; draft-ietf-tram-turn-third-party-
> authz.ad@ietf.org; draft-ietf-tram-turn-third-party-authz.shepherd@ietf.org
> Subject: Re: [tram] Stephen Farrell's Discuss on draft-ietf-tram-turn-third-
> party-authz-15: (with DISCUSS and COMMENT)
> 
> 
> 
> On 30/04/15 09:22, Oleg Moskalenko wrote:
> > On Thu, Apr 30, 2015 at 12:47 AM, Stephen Farrell
> > <stephen.farrell@cs.tcd.ie> wrote:
> >>
> >>
> >> On 30/04/15 02:02, Oleg Moskalenko wrote:
> >
> > Yes, we disagree. With your proposal, you will achieve exactly
> > opposite from what you are declaring.
> >
> > WebRTC server and TURN server are modular servers. They have different
> > semi-independent parts. The essential parts functionality is dictated
> > by the corresponding standards. There is absolutely no necessity to
> > mandate one way or another in the key exchange parts. In reality, as
> > it is usually deployed, the same people are controlling both servers.

Yes, even for the use case where TURN server and WebRTC server are in different administrative domains (e.g. Akamai only providing the relay service) the feedback is that MTI is not required for key exchange. I got  similar response even from OAuth WG http://www.ietf.org/mail-archive/web/oauth/current/msg14321.html using long-term secret b/w AS and RS for OAuth 2.0 self-contained token.

-Tiru