[tram] Sync STUN and SIP auth

Simon Perreault <sperreault@jive.com> Thu, 19 March 2015 13:43 UTC

Return-Path: <sperreault@jive.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D32581A8A7C for <tram@ietfa.amsl.com>; Thu, 19 Mar 2015 06:43:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7kbby3TW0y1S for <tram@ietfa.amsl.com>; Thu, 19 Mar 2015 06:43:20 -0700 (PDT)
Received: from mail-ob0-f175.google.com (mail-ob0-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3F6591A8A39 for <tram@ietf.org>; Thu, 19 Mar 2015 06:43:20 -0700 (PDT)
Received: by obbgg8 with SMTP id gg8so54523138obb.1 for <tram@ietf.org>; Thu, 19 Mar 2015 06:43:19 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=nM38pZBSUPh98pnU117r8Kv2vS87oSBiGaIcm8ZHy+4=; b=G0FwCsP+2LtIK9yFa+/mM3p3EckxobvQlSUhPCwW4M8JsACXpww9u+dT6QZLs0DDoh DK9TbEeVMeDerdsEFZxKybH0BZpIvJOhTPpIOExCS5BfwEJzN6WiCcmP+eC/1TnXZpLE hJuRxwdScCK0a93dumGgDsNOfQVL2bMNX1iUhx0jjrJEClfRaHDzorQt0U+nqHwUjiyB BwNTwQcLv0SDbapXbipJvmzV/wQjsh6y1te35L4Szqfut3a9GZrjrKxWaNBZDo/J1I1B 02l8wqQ8Beedn4+Rs+pGmRZve1qflryToDyCTuGXn28HUA7ktTyLKKa98kh7PyfbEeMb 9Afg==
X-Gm-Message-State: ALoCoQly8Wr4mJDsHO8TS7+PST9JH4Ik2On6aKzFGGhQxlwcT4jsnuAtwLdcam8zdWlo72PEBWDn
X-Received: by 10.60.120.36 with SMTP id kz4mr61857327oeb.47.1426772599713; Thu, 19 Mar 2015 06:43:19 -0700 (PDT)
Received: from Simons-MacBook-Air.local (modemcable233.42-178-173.mc.videotron.ca. [173.178.42.233]) by mx.google.com with ESMTPSA id t8sm697111oib.4.2015.03.19.06.43.18 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 19 Mar 2015 06:43:18 -0700 (PDT)
Message-ID: <550AD275.1010804@jive.com>
Date: Thu, 19 Mar 2015 09:43:17 -0400
From: Simon Perreault <sperreault@jive.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: Marc Petit-Huguenin <petithug@acm.org>, Alan Johnston <alan.b.johnston@gmail.com>, "tram@ietf.org" <tram@ietf.org>
References: <CAKhHsXEcvr8W7qk3Czx1E+DqqVOk_8V_+Bn3ZB5yjXdf=7aGJQ@mail.gmail.com> <550AAF8A.9080205@acm.org>
In-Reply-To: <550AAF8A.9080205@acm.org>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/tram/pDXw-00QMiE2vtbgl82_cOt9_1s>
Subject: [tram] Sync STUN and SIP auth
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Mar 2015 13:43:22 -0000

Le 2015-03-19 07:14, Marc Petit-Huguenin a écrit :
> > Does the use of salted SHA256 for passwords match up with what is planned
> > for SIP?  See:
> > 
> >     https://tools.ietf.org/html/draft-yusef-sipcore-digest-scheme
> > 
> > Does H(A1) match up?  Also, I'm not aware if this draft is moving forward:
> > 
> >     https://tools.ietf.org/html/draft-veltri-sip-alt-auth
> It is not, which is sad because I find it better than draft-yusef-sipcore-digest-scheme.  It also fits better with STUN where the hash algorithm (SHA-1 and now SHA256) has been split off the password hash algorithm (MD5) from the beginning.  draft-yusef-sipcore-digest-scheme does not even talk about the password algorithm, continuing the (I think) rather bad idea of linking the two together.

What you're saying makes sense, yet does not bring us closer to syncing
STUN and SIP auth. I don't know if it is a possible goal, but I feel it
is our duty to at least explore the possibility.

I note that the two drafts above are not working-group drafts. It would
be good to have a chat with the sipcore chairs in Dallas and reach a
common understanding of the situation...

Simon