
From fluffy@iii.ca  Sun Nov  4 09:52:42 2012
Return-Path: <fluffy@iii.ca>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2F3A21F8711 for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 09:52:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lw0lQ9AY+KFD for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 09:52:39 -0800 (PST)
Received: from mxout-07.mxes.net (mxout-07.mxes.net [216.86.168.182]) by ietfa.amsl.com (Postfix) with ESMTP id 9317F21F869A for <p2psip@ietf.org>; Sun,  4 Nov 2012 09:52:39 -0800 (PST)
Received: from [10.21.78.123] (unknown [128.107.239.233]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp.mxes.net (Postfix) with ESMTPSA id 8C9DF22E253; Sun,  4 Nov 2012 12:52:32 -0500 (EST)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 6.2 \(1499\))
From: Cullen Jennings <fluffy@iii.ca>
In-Reply-To: <505B4472.3070400@acm.org>
Date: Sun, 4 Nov 2012 09:23:15 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <71FDFE79-55DF-496F-90DB-BB09C240EF67@iii.ca>
References: <505B4472.3070400@acm.org>
To: Marc Petit-Huguenin <petithug@acm.org>, P2PSIP Mailing List <p2psip@ietf.org>
X-Mailer: Apple Mail (2.1499)
Subject: Re: [P2PSIP] Anycast support in RELOAD, again
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Nov 2012 17:52:42 -0000

I like your solution but given that base is deployable without this, I =
wonder if you could just write this up in a separate draft that was an =
extension to base?


On Sep 20, 2012, at 10:29 , Marc Petit-Huguenin <petithug@acm.org> =
wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>=20
> In Vancouver we decided[1] to remove the support for
> multicast/anycast/broadcast in the RELOAD spec, following a discussion =
back in
> Taipei about problems for supporting anycast.
>=20
> I thought a bit more about the anycast problem, and I found a solution =
to this
> problem that is simple and so that would permit to keep the text in =
-base.
>=20
> To summarize the problem, a bootstrap node cannot be directly running =
on an
> anycast address because the real destination can change at any time, =
and that
> would break DTLS.  That can be solved by adding the IP address of a =
bootstrap
> node not running on the anycast address in the PingResponse, but =
unfortunately
> this is not a compatible change.  There is other problems with this =
approach,
> related to the fact that the Ping must be sent without DTLS (naked =
Ping).
>=20
> But, as per -base section 6.5.1.4, all RELOAD nodes are also STUN =
servers, so
> the naked Ping can be replaced by a STUN connectivity check.  The nice =
thing
> about STUN is that the support for anycast is already there, as a STUN =
server
> running on an anycast address will respond with a 300 Try Alternate =
with an
> ALTERNATE-SERVER attribute containing the IP address of the =
non-anycast node.
>=20
> So the whole problem can be solved by just saying in -base that any =
connection
> to the bootstrap servers must start with a STUN connectivity check.  =
The first
> IP address to successfully respond (i.e. after processing the 300), is =
the one
> where the DTLS/TLS connection must be established to start sending the =
RELOAD
> messages.
>=20
>=20
>=20
> [1] https://www.ietf.org/proceedings/84/minutes/minutes-84-p2psip
> [2] https://www.ietf.org/proceedings/82/minutes/minutes-82-p2psip
>=20
> - --=20
> Marc Petit-Huguenin
> Email: marc@petit-huguenin.org
> Blog: http://blog.marc.petit-huguenin.org
> Profile: http://www.linkedin.com/in/petithug
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (GNU/Linux)
>=20
> iQIcBAEBCAAGBQJQW0RwAAoJECnERZXWan7EZRsP/jDXiBZQBHBJAD8qP2CFp7a7
> wQ5xF5Ms5F1NCyciC5q6ufYs3Yj8ipwQ1cx9vJAJ6E72j1f4ZLMiNxy9Dr750peD
> kK/KAvj5cSMgpp56al+G4J3pdnrIPwx/trRncdX3OAsq8Rtn2GO8lyMFw7RdHK/i
> wrnZCrSa8e2a2jtt/0Ip7xpnaazgkQKn8x9McoQMtPuy2mrUrmZX2uPvLKnc6UQ+
> zl0OfI62PKMv/IryGU9fRIx2vVGRMdu1AgXoIP0jtDnkUo19jcWe3/7ZWzOFeCpT
> tQaIHhDmSyOZ4EVhYTHHLTT42O0BsO/fdgwKT3PvJJQCEPRi16S36oQzS33tWD6h
> bEaGFKeC9QotWq2FHaH/38Cqr+nuIB4azBEpEEwErzWGiy0lPSWiL8sJ7TaTSugJ
> NS5ocDUngf8tZ/3o+sGPypLRMW71BSHvFkWmJ36HuA4Yzg7M68YZto/kw3RdW/J8
> G02COfsf2w0131QPoRUQLQgSOHz6ZP7aiwuqrmKyRhxp1jgaVW1iFY0mOzJI+Nw7
> omRr0Htw1BghfoBkEGWHejH6cymB2ld1+vvwSHgMryC4rLuPrdLBiBf6isFp0xLi
> FKiRVYL3pb4rNrzu2KjaiE6Wv6FhR/Ysdo+XsbxH+jRcfSXLz3i5B65O+wcr0Alj
> Eu1SX15X9nY+FAC2DmjZ
> =3Dx01n
> -----END PGP SIGNATURE-----
> _______________________________________________
> P2PSIP mailing list
> P2PSIP@ietf.org
> https://www.ietf.org/mailman/listinfo/p2psip


From petithug@acm.org  Sun Nov  4 13:15:57 2012
Return-Path: <petithug@acm.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F29B221F890D for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 13:15:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level: 
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id A74ieQ4IR638 for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 13:15:55 -0800 (PST)
Received: from implementers.org (implementers.org [IPv6:2604:3400:dc1:41:216:3eff:fe5b:8240]) by ietfa.amsl.com (Postfix) with ESMTP id 3127821F8839 for <p2psip@ietf.org>; Sun,  4 Nov 2012 13:15:55 -0800 (PST)
Received: from [IPv6:2001:df8:0:64:c617:feff:feb6:86ed] (unknown [IPv6:2001:df8:0:64:c617:feff:feb6:86ed]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by implementers.org (Postfix) with ESMTPS id EBF0C213D1; Sun,  4 Nov 2012 21:15:53 +0000 (UTC)
Message-ID: <5096DB11.4040001@acm.org>
Date: Sun, 04 Nov 2012 13:16:01 -0800
From: Marc Petit-Huguenin <petithug@acm.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.10) Gecko/20121027 Icedove/10.0.10
MIME-Version: 1.0
To: Cullen Jennings <fluffy@iii.ca>
References: <505B4472.3070400@acm.org> <71FDFE79-55DF-496F-90DB-BB09C240EF67@iii.ca>
In-Reply-To: <71FDFE79-55DF-496F-90DB-BB09C240EF67@iii.ca>
X-Enigmail-Version: 1.4.1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Cc: P2PSIP Mailing List <p2psip@ietf.org>
Subject: Re: [P2PSIP] Anycast support in RELOAD, again
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 04 Nov 2012 21:15:57 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 11/04/2012 08:23 AM, Cullen Jennings wrote:
> 
> I like your solution but given that base is deployable without this, I
> wonder if you could just write this up in a separate draft that was an
> extension to base?

Sure, in this case remove all the stuff in -base related to anycast/multicast
and broadcast (as agreed in Vancouver), and I'll start working on a draft with
the bits removed from -base, plus my proposal.  I may even be able to do that
and publish before the P2PSIP WG meeting.

As the new draft will take text from -base, what authors from -base should I
add to the new draft?

Thanks.

> 
> 
> On Sep 20, 2012, at 10:29 , Marc Petit-Huguenin <petithug@acm.org> wrote:
> 
> In Vancouver we decided[1] to remove the support for 
> multicast/anycast/broadcast in the RELOAD spec, following a discussion
> back in Taipei about problems for supporting anycast.
> 
> I thought a bit more about the anycast problem, and I found a solution to 
> this problem that is simple and so that would permit to keep the text in 
> -base.
> 
> To summarize the problem, a bootstrap node cannot be directly running on an
>  anycast address because the real destination can change at any time, and 
> that would break DTLS.  That can be solved by adding the IP address of a 
> bootstrap node not running on the anycast address in the PingResponse, but 
> unfortunately this is not a compatible change.  There is other problems
> with this approach, related to the fact that the Ping must be sent without
> DTLS (naked Ping).
> 
> But, as per -base section 6.5.1.4, all RELOAD nodes are also STUN servers, 
> so the naked Ping can be replaced by a STUN connectivity check.  The nice 
> thing about STUN is that the support for anycast is already there, as a
> STUN server running on an anycast address will respond with a 300 Try
> Alternate with an ALTERNATE-SERVER attribute containing the IP address of
> the non-anycast node.
> 
> So the whole problem can be solved by just saying in -base that any 
> connection to the bootstrap servers must start with a STUN connectivity 
> check.  The first IP address to successfully respond (i.e. after
> processing the 300), is the one where the DTLS/TLS connection must be
> established to start sending the RELOAD messages.
> 
> 
> 
> [1] https://www.ietf.org/proceedings/84/minutes/minutes-84-p2psip [2] 
> https://www.ietf.org/proceedings/82/minutes/minutes-82-p2psip
> 
>> _______________________________________________ P2PSIP mailing list 
>> P2PSIP@ietf.org https://www.ietf.org/mailman/listinfo/p2psip
> 

- -- 
Marc Petit-Huguenin
Personal email: marc@petit-huguenin.org
Professional email: petithug@acm.org
Blog: http://blog.marc.petit-huguenin.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJQltsPAAoJECnERZXWan7EK5oQALoq1+ROmxiOlaBMGw2/E6jy
ZDOPtblDCrubxPyazQypPphkD/zDkqsVwYjXEUonbo8C2RCwUhjJLPwYBdp7hiZf
PPsYxBDrSn3rGe8rf9A1S+PaKmcbExrbZhJghycW84qN8T6tJREDqD8Wh37eS/Tk
jyycIYOkLHfttL1EA78Q/tj9ogXwdBqOH5AAnlfjn6StmaLZ/2Ro1TWwoGMTR8Pn
VBowlw3JpwsGxOc5EbDO9UsKsDTVw3cLOl3fZHWh+mFhf/aCgfipzXaVNlb4K4Gk
vK19H2y5Jhf+T7TdJVsz5qmtJBmXszDDt+5mTJwWKO8qSv+/yR7iczzItFtrmFnE
6ifEtEFCrEVsoNlYdeZtMJKCo+LTdEPSh3vlg+c2NOgZ/mJsAJYYz8bf1tQ5fA1C
3o0lP+hPbHqTTrfKNY/SM11IDygNMhhwXvLngNC+0uC5rhwZgNGOUZJDi2mIHTg+
ZdfPJ8DU77TmPN1yJZeVRvBj+azICD/9qSBT69Hs+HkE/9MGnQ4pojgNRtWUEqb0
Xi8HWPcQpCAzom3wq1zp8HDK7G3w1ql+wjC4/oN+caohcbXsJRWFMVLSklPAH5Vw
eCd2U5vmSSFA74Md3I8eYrkcLLsvIgcuzFjhQt8X+GAxxNgLZiW4z3o99HogHyQe
1/bwYxOivTdeuCP296pl
=UK5L
-----END PGP SIGNATURE-----

From fluffy@iii.ca  Sun Nov  4 16:08:05 2012
Return-Path: <fluffy@iii.ca>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7BF221F8724 for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 16:08:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fPy-jrWPmHSD for <p2psip@ietfa.amsl.com>; Sun,  4 Nov 2012 16:08:05 -0800 (PST)
Received: from mxout-07.mxes.net (mxout-07.mxes.net [216.86.168.182]) by ietfa.amsl.com (Postfix) with ESMTP id C459621F862D for <p2psip@ietf.org>; Sun,  4 Nov 2012 16:08:04 -0800 (PST)
Received: from sjc-vpn5-979.cisco.com (unknown [128.107.239.233]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp.mxes.net (Postfix) with ESMTPSA id 712D422E255; Sun,  4 Nov 2012 19:07:57 -0500 (EST)
Content-Type: text/plain; charset=windows-1252
Mime-Version: 1.0 (Mac OS X Mail 6.2 \(1499\))
From: Cullen Jennings <fluffy@iii.ca>
In-Reply-To: <5096DB11.4040001@acm.org>
Date: Sun, 4 Nov 2012 19:10:16 -0500
Content-Transfer-Encoding: quoted-printable
Message-Id: <0E514254-585B-41DB-A116-BDDC09961763@iii.ca>
References: <505B4472.3070400@acm.org> <71FDFE79-55DF-496F-90DB-BB09C240EF67@iii.ca> <5096DB11.4040001@acm.org>
To: Marc Petit-Huguenin <petithug@acm.org>
X-Mailer: Apple Mail (2.1499)
Cc: P2PSIP Mailing List <p2psip@ietf.org>
Subject: Re: [P2PSIP] Anycast support in RELOAD, again
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Nov 2012 00:08:06 -0000

On Nov 4, 2012, at 16:16 , Marc Petit-Huguenin <petithug@acm.org> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>=20
> On 11/04/2012 08:23 AM, Cullen Jennings wrote:
>>=20
>> I like your solution but given that base is deployable without this, =
I
>> wonder if you could just write this up in a separate draft that was =
an
>> extension to base?
>=20
> Sure, in this case remove all the stuff in -base related to =
anycast/multicast
> and broadcast (as agreed in Vancouver), and I'll start working on a =
draft with
> the bits removed from -base, plus my proposal.  I may even be able to =
do that
> and publish before the P2PSIP WG meeting.
>=20
> As the new draft will take text from -base, what authors from -base =
should I
> add to the new draft?

I don't think you need to take any of them. You might put in =
acknowledgment that explained the original source=85.

>=20
> Thanks.
>=20
>>=20
>>=20
>> On Sep 20, 2012, at 10:29 , Marc Petit-Huguenin <petithug@acm.org> =
wrote:
>>=20
>> In Vancouver we decided[1] to remove the support for=20
>> multicast/anycast/broadcast in the RELOAD spec, following a =
discussion
>> back in Taipei about problems for supporting anycast.
>>=20
>> I thought a bit more about the anycast problem, and I found a =
solution to=20
>> this problem that is simple and so that would permit to keep the text =
in=20
>> -base.
>>=20
>> To summarize the problem, a bootstrap node cannot be directly running =
on an
>> anycast address because the real destination can change at any time, =
and=20
>> that would break DTLS.  That can be solved by adding the IP address =
of a=20
>> bootstrap node not running on the anycast address in the =
PingResponse, but=20
>> unfortunately this is not a compatible change.  There is other =
problems
>> with this approach, related to the fact that the Ping must be sent =
without
>> DTLS (naked Ping).
>>=20
>> But, as per -base section 6.5.1.4, all RELOAD nodes are also STUN =
servers,=20
>> so the naked Ping can be replaced by a STUN connectivity check.  The =
nice=20
>> thing about STUN is that the support for anycast is already there, as =
a
>> STUN server running on an anycast address will respond with a 300 Try
>> Alternate with an ALTERNATE-SERVER attribute containing the IP =
address of
>> the non-anycast node.
>>=20
>> So the whole problem can be solved by just saying in -base that any=20=

>> connection to the bootstrap servers must start with a STUN =
connectivity=20
>> check.  The first IP address to successfully respond (i.e. after
>> processing the 300), is the one where the DTLS/TLS connection must be
>> established to start sending the RELOAD messages.
>>=20
>>=20
>>=20
>> [1] https://www.ietf.org/proceedings/84/minutes/minutes-84-p2psip [2]=20=

>> https://www.ietf.org/proceedings/82/minutes/minutes-82-p2psip
>>=20
>>> _______________________________________________ P2PSIP mailing list=20=

>>> P2PSIP@ietf.org https://www.ietf.org/mailman/listinfo/p2psip
>>=20
>=20
> - --=20
> Marc Petit-Huguenin
> Personal email: marc@petit-huguenin.org
> Professional email: petithug@acm.org
> Blog: http://blog.marc.petit-huguenin.org
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (GNU/Linux)
>=20
> iQIcBAEBCAAGBQJQltsPAAoJECnERZXWan7EK5oQALoq1+ROmxiOlaBMGw2/E6jy
> ZDOPtblDCrubxPyazQypPphkD/zDkqsVwYjXEUonbo8C2RCwUhjJLPwYBdp7hiZf
> PPsYxBDrSn3rGe8rf9A1S+PaKmcbExrbZhJghycW84qN8T6tJREDqD8Wh37eS/Tk
> jyycIYOkLHfttL1EA78Q/tj9ogXwdBqOH5AAnlfjn6StmaLZ/2Ro1TWwoGMTR8Pn
> VBowlw3JpwsGxOc5EbDO9UsKsDTVw3cLOl3fZHWh+mFhf/aCgfipzXaVNlb4K4Gk
> vK19H2y5Jhf+T7TdJVsz5qmtJBmXszDDt+5mTJwWKO8qSv+/yR7iczzItFtrmFnE
> 6ifEtEFCrEVsoNlYdeZtMJKCo+LTdEPSh3vlg+c2NOgZ/mJsAJYYz8bf1tQ5fA1C
> 3o0lP+hPbHqTTrfKNY/SM11IDygNMhhwXvLngNC+0uC5rhwZgNGOUZJDi2mIHTg+
> ZdfPJ8DU77TmPN1yJZeVRvBj+azICD/9qSBT69Hs+HkE/9MGnQ4pojgNRtWUEqb0
> Xi8HWPcQpCAzom3wq1zp8HDK7G3w1ql+wjC4/oN+caohcbXsJRWFMVLSklPAH5Vw
> eCd2U5vmSSFA74Md3I8eYrkcLLsvIgcuzFjhQt8X+GAxxNgLZiW4z3o99HogHyQe
> 1/bwYxOivTdeuCP296pl
> =3DUK5L
> -----END PGP SIGNATURE-----


From internet-drafts@ietf.org  Mon Nov  5 08:11:59 2012
Return-Path: <internet-drafts@ietf.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E4D4921F8876; Mon,  5 Nov 2012 08:11:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.561
X-Spam-Level: 
X-Spam-Status: No, score=-102.561 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dS7RmUSATOO3; Mon,  5 Nov 2012 08:11:58 -0800 (PST)
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB12921F887C; Mon,  5 Nov 2012 08:11:56 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 4.35
Message-ID: <20121105161156.23349.8399.idtracker@ietfa.amsl.com>
Date: Mon, 05 Nov 2012 08:11:56 -0800
Cc: p2psip@ietf.org
Subject: [P2PSIP] I-D Action: draft-ietf-p2psip-base-23.txt
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Nov 2012 16:11:59 -0000

A New Internet-Draft is available from the on-line Internet-Drafts director=
ies.
 This draft is a work item of the Peer-to-Peer Session Initiation Protocol =
Working Group of the IETF.

	Title           : REsource LOcation And Discovery (RELOAD) Base Protocol
	Author(s)       : Cullen Jennings
                          Bruce B. Lowekamp
                          Eric Rescorla
                          Salman A. Baset
                          Henning Schulzrinne
	Filename        : draft-ietf-p2psip-base-23.txt
	Pages           : 167
	Date            : 2012-11-05

Abstract:
   This specification defines REsource LOcation And Discovery (RELOAD),
   a peer-to-peer (P2P) signaling protocol for use on the Internet.  A
   P2P signaling protocol provides its clients with an abstract storage
   and messaging service between a set of cooperating peers that form
   the overlay network.  RELOAD is designed to support a P2P Session
   Initiation Protocol (P2PSIP) network, but can be utilized by other
   applications with similar requirements by defining new usages that
   specify the kinds of data that must be stored for a particular
   application.  RELOAD defines a security model based on a certificate
   enrollment service that provides unique identities.  NAT traversal is
   a fundamental service of the protocol.  RELOAD also allows access
   from "client" nodes that do not need to route traffic or store data
   for others.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-p2psip-base

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-ietf-p2psip-base-23

A diff from the previous version is available at:
http://www.ietf.org/rfcdiff?url2=3Ddraft-ietf-p2psip-base-23


Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From dean.willis@softarmor.com  Mon Nov  5 08:41:49 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 734C021F8822 for <p2psip@ietfa.amsl.com>; Mon,  5 Nov 2012 08:41:49 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7aHyzeqXe+Vt for <p2psip@ietfa.amsl.com>; Mon,  5 Nov 2012 08:41:48 -0800 (PST)
Received: from mail-da0-f44.google.com (mail-da0-f44.google.com [209.85.210.44]) by ietfa.amsl.com (Postfix) with ESMTP id B59B721F880E for <p2psip@ietf.org>; Mon,  5 Nov 2012 08:41:34 -0800 (PST)
Received: by mail-da0-f44.google.com with SMTP id h15so2750581dan.31 for <p2psip@ietf.org>; Mon, 05 Nov 2012 08:41:34 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer; bh=0OMxhOKvyQ2toztxZ9rb7zV6TnjbE75HGn14vqL1stU=; b=UBtWWrh5OTMyreZQs5XMUfoUTSiMnqYkefB7Su5DsKb03MBW7kBaSTKOF8JggHKrix CtkkZQK5Ug0mKTsa9eh4SLG3K3jo0jqQwe4XNvEZRtjdEy0RgxyuN1XSkGPKZqIYRVdk ltROIvYk7ZMs022Tgxw3TnhUHfwowYUpHGfhI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer:x-gm-message-state; bh=0OMxhOKvyQ2toztxZ9rb7zV6TnjbE75HGn14vqL1stU=; b=FkXLhaaHu1GVus5mebGW0OlAspZ0YXzJjBL3GyxMQ32R6jw2FrEGGwUdm04DOU1le3 PQcIQHkX8oKUyGsqi3HpI1pHQTELIzxnknqda+xKe75SJ1kaXiQGvC8luUFsWgg0geW9 kDh8DfjIvK0xNvmUTyj8WYSt5Kh/enMiWOBCsVSrQiaObgBOJkwIAiuj83jnWFAXG+Qu P+C5d6mNZtltS2jRFQyP3kojL0AUgIBY9lNTG8uGxHqKES6MN1aGdu/rKtg4LgCbO8tI KjivL+rHZrQ7SPrBgpvWixZwxn3z+PqZS6PJZOU6DH6FhsFqn21Q7Rt14yxsiE3fQpVt ByVA==
Received: by 10.66.85.69 with SMTP id f5mr29782069paz.50.1352133694319; Mon, 05 Nov 2012 08:41:34 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id lb3sm10791186pbc.73.2012.11.05.08.41.32 (version=TLSv1/SSLv3 cipher=OTHER); Mon, 05 Nov 2012 08:41:33 -0800 (PST)
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <C1C42490-0963-414E-B17D-9516CEBB2E1D@softarmor.com>
Date: Mon, 5 Nov 2012 10:41:31 -0600
To: p2psip@ietf.org
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQmaB9hhhwS8ewMkHj8U7XB0X3V8E/o2cQOKhPM+o0m62H1pVOaaoMDgq899OZwLKvN3Zg2L
Subject: [P2PSIP] RELOAD base -23 posted
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Nov 2012 16:41:49 -0000

I pulled together the "consensus" items from meeting 84 along with many =
of the nits Marc reported, and have submitted a -23 version.=20

To make it easier for you lazy, overworked, unconcerned, distracted, =
intoxicated, medicated, sleepless or otherwise disadvantaged folks (I'm =
planning to be in all the above categories this week)  I've posted a =
side-by-side diff from -22 at:

=
http://www.softarmor.com/dwillis/ietf/draft-ietf-p2psip-base-22.txt-draft-=
ietf-p2psip-base-23.txt.html

--
Dean


From dean.willis@softarmor.com  Tue Nov  6 13:32:52 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2267A21F8748 for <p2psip@ietfa.amsl.com>; Tue,  6 Nov 2012 13:32:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T7XvDcv7Tx8D for <p2psip@ietfa.amsl.com>; Tue,  6 Nov 2012 13:32:51 -0800 (PST)
Received: from mail-pb0-f44.google.com (mail-pb0-f44.google.com [209.85.160.44]) by ietfa.amsl.com (Postfix) with ESMTP id 8B6DC21F8488 for <p2psip@ietf.org>; Tue,  6 Nov 2012 13:32:51 -0800 (PST)
Received: by mail-pb0-f44.google.com with SMTP id ro8so711578pbb.31 for <p2psip@ietf.org>; Tue, 06 Nov 2012 13:32:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer; bh=vd7W2DAwh72TC/i8vP0KOoKQOIqpVnCQaEnJ64z37Pc=; b=EftO3JtYyGYupybh/Re24Txz2r19r5tVf4POC+oQfNAMGU4imjRsz0MhFR/JjzgRCx Jp/eXA+/TJTsmvZ48hLk2XUZDREFm42xtLI/t+0w7mxnESL+VeSClX5USJry6rKhq7hQ zTpSkDmm0kZWd9JrKLcuP0NcZXrfOQ1l7Hwv4=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer:x-gm-message-state; bh=vd7W2DAwh72TC/i8vP0KOoKQOIqpVnCQaEnJ64z37Pc=; b=cWyoAMG5NP4hwT9T927C3c9sylcNfSAxB+SCGBbD5U4UGA7rRKk7Fvxc1Aj0d2HWrR n4791yfTFZKZuMweRZArZRr9SAGS8huy63bUB3OosmwZMTmTFSjd3n+TRylXl/fs4MQF tEX9gWOtwMQnYYGC5DUmdum2cIkscB6xKGSwrqlXapWvGKhWveYmjgtELC1w7HYL5/Lb Mlra50tmaA5UqPzWsoLFPK3ceL8phfeEjv9xuwVAHOC2BySaQSPTEnsFJlWUF7pluWuK w6BHvUhN0QlR0kh4425vsza+dzcyM/w25DnazwNy3I17R11sPpDJdRzqvuZLeWYGPMVD 2Mrw==
Received: by 10.66.81.163 with SMTP id b3mr110508pay.49.1352237571188; Tue, 06 Nov 2012 13:32:51 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id ty4sm12895447pbc.57.2012.11.06.13.32.49 (version=TLSv1/SSLv3 cipher=OTHER); Tue, 06 Nov 2012 13:32:50 -0800 (PST)
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <2D214943-6CC3-4410-AA5E-E503F0BC31A2@softarmor.com>
Date: Tue, 6 Nov 2012 15:32:47 -0600
To: p2psip@ietf.org
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQl+jIN3Q0Ddql8WhY8dXgy5mfnE9nMKhGv3B8XgOzd7vTqlh0DBDzX7TdJcUGMab1pGQtsT
Subject: [P2PSIP] tracking IESG Discuss statements on reload-base
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Nov 2012 21:32:52 -0000

After integrating the outstanding consensus points into account for the =
-23 draft, Marc and I spent a couple of hours looking at the various =
IESG input.

It's not promising. I'm currently tracking 188 "Discuss" points.

Some of these are simple typos. Some are requests for rewording for =
clarity. One is a request to include Mary Barnes' GEN-ART review =
feedback, which I haven't looked at but expect it includes a few hundred =
changes.

By far the most troubling are the recurrent views that the document =
needs to be re-structured for clarity, probably with a clean demarc =
between the base protocol and the topology plugins like Chord.  One =
shouldn't have to understand Chord or even the princpals of a DHT for =
the base document to make sense.

The ADs would apparently also like to see a clean "high level" view of =
the architecture and principals of operation, with dives into protocol =
specification, security consideration, and OAMP.  And maybe see it split =
into a couple of smaller documents.

--
Dean=

From dean.willis@softarmor.com  Tue Nov  6 14:23:12 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E5BD21F8BAC for <p2psip@ietfa.amsl.com>; Tue,  6 Nov 2012 14:23:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LWC50vAFKYi3 for <p2psip@ietfa.amsl.com>; Tue,  6 Nov 2012 14:23:11 -0800 (PST)
Received: from mail-da0-f44.google.com (mail-da0-f44.google.com [209.85.210.44]) by ietfa.amsl.com (Postfix) with ESMTP id A1B6721F8BB3 for <p2psip@ietf.org>; Tue,  6 Nov 2012 14:23:11 -0800 (PST)
Received: by mail-da0-f44.google.com with SMTP id h15so398070dan.31 for <p2psip@ietf.org>; Tue, 06 Nov 2012 14:23:11 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer; bh=VlPxgC54pAa56TZhNiw1u5KK9NZc6hny80SEoKUqxxU=; b=DlPL5cuEM2OLapCn+F+mnwwc66VM9+CAr22vWivz7WnfMXTHkes+1y5hE7JAwS9kDD WLOZAAPi5xNSODEFGO3pr3kLV2iiSqQW35qxYq1GZx66TXu/sEKZCdeagxiUGZTVHamM rGFalL4IcdzlMrwm53Z4dxOxG60qklR6ahYCA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer :x-gm-message-state; bh=VlPxgC54pAa56TZhNiw1u5KK9NZc6hny80SEoKUqxxU=; b=H4ZY1CT5qKseOvuVWqp63KrxGSYDK6MZAq/w7tZYYA6lrOSH0SdchFIeJy5i6Z1uBA 1tVhS3Pp/uicUsGQ/S4bbqJCjs81MqybHEMXc/WsJT/9Wvx+r+tDY8ATegFwqvi/gGk2 ja6/TQY0c2DavXfLAPZfhHspTIkEOfPNQ32F+gVOlNkS1k3aOKsFtfrE9lGdTtM1sReV ijC/0IjbQ70tGNqDDNIj6+6oBc+MBrpy7Ud2qvFs8jWGPMmkyS6+eWxbUm/K8/SyWJff zijQ94dsEeB+0VtNb1Nm2gZuMae4L/9d3IlLcvJIgK8fcErXlZ+iH5AbJn91hktonteO Uwrg==
Received: by 10.66.87.34 with SMTP id u2mr6391008paz.82.1352240591339; Tue, 06 Nov 2012 14:23:11 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id j8sm13082751paz.30.2012.11.06.14.23.09 (version=TLSv1/SSLv3 cipher=OTHER); Tue, 06 Nov 2012 14:23:10 -0800 (PST)
References: <2D214943-6CC3-4410-AA5E-E503F0BC31A2@softarmor.com>
In-Reply-To: <2D214943-6CC3-4410-AA5E-E503F0BC31A2@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <084554EE-02CF-4C87-B838-31D17A6350CF@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Tue, 6 Nov 2012 16:23:07 -0600
To: Dean Willis <dean.willis@softarmor.com>
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQn8uFIFHvCOHhEWry7qsX9Yey3dUqjggYUgOMUKFZBqpBNjVZCy0AT+JNjTMT9JOPdLt5my
Cc: p2psip@ietf.org
Subject: Re: [P2PSIP] tracking IESG Discuss statements on reload-base
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Nov 2012 22:23:12 -0000

Oh yeah, I meant to include this outline of the "discuss" points.

http://www.softarmor.com/dwillis/ietf/reload-base-discuss.html

On Nov 6, 2012, at 3:32 PM, Dean Willis wrote:

>=20
> After integrating the outstanding consensus points into account for =
the -23 draft, Marc and I spent a couple of hours looking at the various =
IESG input.
>=20
> It's not promising. I'm currently tracking 188 "Discuss" points.
>=20
> Some of these are simple typos. Some are requests for rewording for =
clarity. One is a request to include Mary Barnes' GEN-ART review =
feedback, which I haven't looked at but expect it includes a few hundred =
changes.
>=20
> By far the most troubling are the recurrent views that the document =
needs to be re-structured for clarity, probably with a clean demarc =
between the base protocol and the topology plugins like Chord.  One =
shouldn't have to understand Chord or even the princpals of a DHT for =
the base document to make sense.
>=20
> The ADs would apparently also like to see a clean "high level" view of =
the architecture and principals of operation, with dives into protocol =
specification, security consideration, and OAMP.  And maybe see it split =
into a couple of smaller documents.
>=20
> --
> Dean


From Jan.Seedorf@neclab.eu  Wed Nov  7 08:06:46 2012
Return-Path: <Jan.Seedorf@neclab.eu>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7908321F8C73 for <p2psip@ietfa.amsl.com>; Wed,  7 Nov 2012 08:06:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jZ+dDVnM-e0k for <p2psip@ietfa.amsl.com>; Wed,  7 Nov 2012 08:06:45 -0800 (PST)
Received: from mailer1.neclab.eu (mailer1.neclab.eu [195.37.70.40]) by ietfa.amsl.com (Postfix) with ESMTP id 156FD21F8C69 for <p2psip@ietf.org>; Wed,  7 Nov 2012 08:06:41 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by mailer1.neclab.eu (Postfix) with ESMTP id 45A54102493 for <p2psip@ietf.org>; Wed,  7 Nov 2012 17:06:39 +0100 (CET)
X-Virus-Scanned: Amavisd on Debian GNU/Linux (netlab.nec.de)
Received: from mailer1.neclab.eu ([127.0.0.1]) by localhost (atlas-a.office.hd [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vOgEwUuM-Les for <p2psip@ietf.org>; Wed,  7 Nov 2012 17:06:39 +0100 (CET)
Received: from METHONE.office.hd (methone.office.hd [192.168.24.54]) by mailer1.neclab.eu (Postfix) with ESMTP id 2AAB1102462 for <p2psip@ietf.org>; Wed,  7 Nov 2012 17:06:34 +0100 (CET)
Received: from DAPHNIS.office.hd ([169.254.2.239]) by METHONE.office.hd ([192.168.24.54]) with mapi id 14.01.0323.003; Wed, 7 Nov 2012 17:06:34 +0100
From: Jan Seedorf <Jan.Seedorf@neclab.eu>
To: "p2psip@ietf.org" <p2psip@ietf.org>
Thread-Topic: Some literature pointers to work on DHT Anonymity ...
Thread-Index: Ac28/4JADxEnr7bjT4qeYlIgO+9YNA==
Date: Wed, 7 Nov 2012 16:06:15 +0000
Message-ID: <2779C9F0771F974CAD742BAE6D9904FE553859C8@DAPHNIS.office.hd>
Accept-Language: de-DE, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.7.0.207]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: [P2PSIP] Some literature pointers to work on DHT Anonymity ...
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Nov 2012 16:06:46 -0000

Hi Marc and all,

As discussed yesterday in the P2PSIP session, here are some papers that hav=
e proposed mechanisms for DHT routing anonymity (most of them are based on =
Onion routing). I guess this is very related to your document draft-petithu=
guenin-p2psip-reload-anonymous-01. In particular, the first paper below foc=
usses on P2PSIP.

-- A. Fessi, N. Evans, H. Niedermayer, and R. Holz, \Pr2-P2PSIP: Privacy Pr=
eserving P2P Signaling for VoIP and IM," in Principles, Systems and Applica=
tions of IP Telecommunications (IPTComm). iptcomm.org, 2010, last
visited on June 4th, 2012. [Online]. Available: http://iptcomm.org/iptcomm2=
010/ IPTComm2010-Proceedings.pdf

-- J. McLachlan, A. Tran, N. Hopper, and Y. Kim, \Scalable Onion Routing wi=
th Torsk," in Proceedings of the 16th ACM Conference on Computer and Commun=
ications Security (CCS). ACM. New York, NY, USA, 2009.

-- A. Panchenko, S. Richter, and A. Rache, \NISAN: Network Information Serv=
ice for Anonymization Networks," in Proceedings of the 16th ACM Conference =
on Computer and Communications Security (CCS). ACM, New York, NY, USA, 2009=
.

-- Q. Wang and N. Borisov, \Octopus: A Secure and Anonymous DHT Lookup," in=
 32nd International Conference on Distributed Computing Systems (ICDCS). IE=
EE Computer Society, Washington DC, USA, 2012.

 - Jan
=20


From loopp2psip@gmail.com  Thu Nov  8 03:55:00 2012
Return-Path: <loopp2psip@gmail.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1081421F8B6C for <p2psip@ietfa.amsl.com>; Thu,  8 Nov 2012 03:55:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.598
X-Spam-Level: 
X-Spam-Status: No, score=-3.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9-2e15Zq66GG for <p2psip@ietfa.amsl.com>; Thu,  8 Nov 2012 03:54:58 -0800 (PST)
Received: from mail-wi0-f170.google.com (mail-wi0-f170.google.com [209.85.212.170]) by ietfa.amsl.com (Postfix) with ESMTP id 6911E21F8B6A for <p2psip@ietf.org>; Thu,  8 Nov 2012 03:54:58 -0800 (PST)
Received: by mail-wi0-f170.google.com with SMTP id hm9so1475381wib.1 for <p2psip@ietf.org>; Thu, 08 Nov 2012 03:54:57 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to:x-mailer; bh=2NTmYX6sU7Y9G1t0S1By9JvHI+GbUEbruR6miqmVBpM=; b=ljYiTKfayeOWsdD++tT3XinoP9+IrpxvQ6x1f2by02x+cE8nh11g5K1q6JT0wwt60U jBAv12P+R43sA0MfYdIP7KaNNZdRYrUs1M0z4p3fceQNLGcqOqer+F+3HzYm7EZL3voE 3ucZOm5yh1XPfiN4t3rJwnAAZz1wYR5tZS67d/KTLEWQmet1QlgB6geTFZ3Um5TNS0I+ gyTA8ToJTnsfqxpT8oBHxRO3nknDwakyzOXWQSqFH/Ykcqso9yCEJc6oAFkAjMnO63ex 6SOvGjEciRhBDHrHnKhA+pF1Ra32r7BVARtL61OZIrp/MJUOi12+hkcKtWOSl4gT/95/ li4Q==
Received: by 10.180.83.130 with SMTP id q2mr2732065wiy.22.1352375697292; Thu, 08 Nov 2012 03:54:57 -0800 (PST)
Received: from [163.117.207.99] ([163.117.207.99]) by mx.google.com with ESMTPS id dt9sm7037535wib.1.2012.11.08.03.54.49 (version=TLSv1/SSLv3 cipher=OTHER); Thu, 08 Nov 2012 03:54:56 -0800 (PST)
Mime-Version: 1.0 (Apple Message framework v1283)
Content-Type: multipart/alternative; boundary="Apple-Mail=_A18E5452-19DE-4E36-A0C6-250553E92A31"
From: Diego Suarez <loopp2psip@gmail.com>
In-Reply-To: <2779C9F0771F974CAD742BAE6D9904FE553859C8@DAPHNIS.office.hd>
Date: Thu, 8 Nov 2012 12:54:48 +0100
Message-Id: <D23EBB94-B319-4A46-B287-32C51EE10738@gmail.com>
References: <2779C9F0771F974CAD742BAE6D9904FE553859C8@DAPHNIS.office.hd>
To: Jan Seedorf <Jan.Seedorf@neclab.eu>
X-Mailer: Apple Mail (2.1283)
Cc: "p2psip@ietf.org" <p2psip@ietf.org>
Subject: Re: [P2PSIP] Some literature pointers to work on DHT Anonymity ...
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Nov 2012 11:55:00 -0000

--Apple-Mail=_A18E5452-19DE-4E36-A0C6-250553E92A31
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Hi all,

Related to this topic, and in case it is of interest to the group, in =
the following paper we have studied different mechanism for routing =
anonymity ( like using external anonymous systems, routing variations or =
headers obfuscation ) among other security aspects of P2PSIP.

D. Touceda, J.M. Sierra, A. Izquierdo and H. Schulzrinne, "Survey of =
Attacks and Defenses on P2PSIP Communications", IEEE Communications =
Surveys and Tutorials, Volume 14, Issue 3, pp. 750-783, Third Quarter =
2012.=20

cheers

On Nov 7, 2012, at 5:06 PM, Jan Seedorf wrote:

> Hi Marc and all,
>=20
> As discussed yesterday in the P2PSIP session, here are some papers =
that have proposed mechanisms for DHT routing anonymity (most of them =
are based on Onion routing). I guess this is very related to your =
document draft-petithuguenin-p2psip-reload-anonymous-01. In particular, =
the first paper below focusses on P2PSIP.
>=20
> -- A. Fessi, N. Evans, H. Niedermayer, and R. Holz, \Pr2-P2PSIP: =
Privacy Preserving P2P Signaling for VoIP and IM," in Principles, =
Systems and Applications of IP Telecommunications (IPTComm). =
iptcomm.org, 2010, last
> visited on June 4th, 2012. [Online]. Available: =
http://iptcomm.org/iptcomm2010/ IPTComm2010-Proceedings.pdf
>=20
> -- J. McLachlan, A. Tran, N. Hopper, and Y. Kim, \Scalable Onion =
Routing with Torsk," in Proceedings of the 16th ACM Conference on =
Computer and Communications Security (CCS). ACM. New York, NY, USA, =
2009.
>=20
> -- A. Panchenko, S. Richter, and A. Rache, \NISAN: Network Information =
Service for Anonymization Networks," in Proceedings of the 16th ACM =
Conference on Computer and Communications Security (CCS). ACM, New York, =
NY, USA, 2009.
>=20
> -- Q. Wang and N. Borisov, \Octopus: A Secure and Anonymous DHT =
Lookup," in 32nd International Conference on Distributed Computing =
Systems (ICDCS). IEEE Computer Society, Washington DC, USA, 2012.
>=20
> - Jan
>=20
>=20
> _______________________________________________
> P2PSIP mailing list
> P2PSIP@ietf.org
> https://www.ietf.org/mailman/listinfo/p2psip


--Apple-Mail=_A18E5452-19DE-4E36-A0C6-250553E92A31
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; =
"><div>Hi all,</div><div><br></div><div>Related to this topic, and in =
case it is of interest to the group, in the following paper we have =
studied different mechanism for routing anonymity ( like using external =
anonymous systems, routing variations or headers obfuscation ) among =
other security aspects of P2PSIP.</div><div><br></div>
		<div><span class=3D"Apple-style-span" =
style=3D"font-family: CMR10; font-size: 13px; ">D. Touceda, J.M. Sierra, =
A. Izquierdo and H. Schulzrinne, "Survey of Attacks and Defenses on =
P2PSIP
Communications", IEEE Communications Surveys and Tutorials, Volume 14, =
Issue 3, pp. 750-783, Third Quarter =
2012.</span>&nbsp;</div><div><br></div><div>cheers</div><br><div><div>On =
Nov 7, 2012, at 5:06 PM, Jan Seedorf wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><div>Hi =
Marc and all,<br><br>As discussed yesterday in the P2PSIP session, here =
are some papers that have proposed mechanisms for DHT routing anonymity =
(most of them are based on Onion routing). I guess this is very related =
to your document draft-petithuguenin-p2psip-reload-anonymous-01. In =
particular, the first paper below focusses on P2PSIP.<br><br>-- A. =
Fessi, N. Evans, H. Niedermayer, and R. Holz, \Pr2-P2PSIP: Privacy =
Preserving P2P Signaling for VoIP and IM," in Principles, Systems and =
Applications of IP Telecommunications (IPTComm). <a =
href=3D"http://iptcomm.org">iptcomm.org</a>, 2010, last<br>visited on =
June 4th, 2012. [Online]. Available: <a =
href=3D"http://iptcomm.org/iptcomm2010/">http://iptcomm.org/iptcomm2010/</=
a> IPTComm2010-Proceedings.pdf<br><br>-- J. McLachlan, A. Tran, N. =
Hopper, and Y. Kim, \Scalable Onion Routing with Torsk," in Proceedings =
of the 16th ACM Conference on Computer and Communications Security =
(CCS). ACM. New York, NY, USA, 2009.<br><br>-- A. Panchenko, S. Richter, =
and A. Rache, \NISAN: Network Information Service for Anonymization =
Networks," in Proceedings of the 16th ACM Conference on Computer and =
Communications Security (CCS). ACM, New York, NY, USA, 2009.<br><br>-- =
Q. Wang and N. Borisov, \Octopus: A Secure and Anonymous DHT Lookup," in =
32nd International Conference on Distributed Computing Systems (ICDCS). =
IEEE Computer Society, Washington DC, USA, 2012.<br><br> - =
Jan<br><br><br>_______________________________________________<br>P2PSIP =
mailing list<br><a =
href=3D"mailto:P2PSIP@ietf.org">P2PSIP@ietf.org</a><br>https://www.ietf.or=
g/mailman/listinfo/p2psip<br></div></blockquote></div><br></body></html>=

--Apple-Mail=_A18E5452-19DE-4E36-A0C6-250553E92A31--

From dean.willis@softarmor.com  Thu Nov  8 14:07:38 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9838D21F88B4 for <p2psip@ietfa.amsl.com>; Thu,  8 Nov 2012 14:07:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dxTFZwFUH77n for <p2psip@ietfa.amsl.com>; Thu,  8 Nov 2012 14:07:37 -0800 (PST)
Received: from mail-pa0-f44.google.com (mail-pa0-f44.google.com [209.85.220.44]) by ietfa.amsl.com (Postfix) with ESMTP id 9E97C21F8836 for <p2psip@ietf.org>; Thu,  8 Nov 2012 14:07:37 -0800 (PST)
Received: by mail-pa0-f44.google.com with SMTP id fb11so2463109pad.31 for <p2psip@ietf.org>; Thu, 08 Nov 2012 14:07:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer; bh=wjnU4Gi7bfvNYaaNnbBKAYewk9sBjTbLoGVfJ7HKfc4=; b=aQMEAhke7Pvp5CzT3CyKP5WczYCmuec3S26gfEbbcoJHCtjLiAvAWWsjdSe18rJ1Kf HfgzJarj4MZFb5lBMHCU/Xz16sdl0P0844rcbvG0jcDWduOHF2Z1SjqFb0F7KMYIEBuS 2oyjlMN6jUTIjEvQKYDJOmIoMhgTZP8uT4K4M=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:from:content-type:message-id:date:to :content-transfer-encoding:mime-version:x-mailer:x-gm-message-state; bh=wjnU4Gi7bfvNYaaNnbBKAYewk9sBjTbLoGVfJ7HKfc4=; b=mdX07Cb9MXUfdIaUpvI8oy/1/EsN9Mh7nFmxgGoGogLvc+2xKVwxRqoHp06b1rzP5x iT288G/Pjh+OCz3hEbTZGT+mlEGsZlORJqFH/3vuwV02ukqU+G7dx3qU5dMSnuk1jrEe Uz9WKYCfifVct7+buQcQTtZ5TUHcLlDb5+bDF6dW2tvrKNReltwhXQEUjvtozGVcNcX6 3c/hhecBar+wGCa56f28u23XhBUT4wLN1WpNVqfA6zrEoSGJO5wbD432WMK/HIM01KBd I7J6mstaxY+G8cv7jD4tY/8b+BVZnyLDUK9VTuznZP6QPJ1SoeIQKCwxSXwnPP7xTF+i G86A==
Received: by 10.68.209.230 with SMTP id mp6mr21141709pbc.8.1352412452616; Thu, 08 Nov 2012 14:07:32 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id qd3sm16129141pbc.29.2012.11.08.14.07.31 (version=TLSv1/SSLv3 cipher=OTHER); Thu, 08 Nov 2012 14:07:31 -0800 (PST)
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <FF0414A2-7F9D-4C8A-B9A9-A103E093E7B1@softarmor.com>
Date: Thu, 8 Nov 2012 16:07:29 -0600
To: p2psip@ietf.org
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQkafcqbeWgoviD4z4F5TWHhfhZqico6poebU86SfV6UBCF4N4XK4APk2gH1HBFBVDctZJgs
Subject: [P2PSIP] Live tracker for known AD issues on p2psip-base
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Nov 2012 22:07:38 -0000

I'm working from a GDocs spreadsheet at:

=
https://docs.google.com/spreadsheet/ccc?key=3D0AnloAbucfY99dHNWTHZXU1JndFl=
ETjE2UzkyNG1ybGc

We've classified 130 or so of the 188 comments received. Most are minor =
edits. Several need to be taken to the list and authors for further =
thought. I'll be sending more on those as we go.

--
Dean=

From dean.willis@softarmor.com  Fri Nov  9 08:30:18 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73AC721F868B for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:30:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cZiWkEVm4HNQ for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:30:16 -0800 (PST)
Received: from mail-pb0-f44.google.com (mail-pb0-f44.google.com [209.85.160.44]) by ietfa.amsl.com (Postfix) with ESMTP id 38B9221F86D8 for <p2psip@ietf.org>; Fri,  9 Nov 2012 08:30:16 -0800 (PST)
Received: by mail-pb0-f44.google.com with SMTP id ro8so3135607pbb.31 for <p2psip@ietf.org>; Fri, 09 Nov 2012 08:30:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer; bh=fTf+bHIw44PnWN4WbBREaXHFKlXpgd+eenlHhrjuMeg=; b=EWg2rqqhlPi9MeEZedt/QYBGgY5ivnHWbQmR0I5ujU9hOL6yIed+1OmkccPof3m0Ah FGQPw2e5Xe5AxHUBnVLCBt8eeooSk8m68ujhMCULP1h6cdxT5a2fVGplFLeZGAAATDSH i8EBld29J2sxgiyZHA8zscT0RSrFzqZEAok2A=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer:x-gm-message-state; bh=fTf+bHIw44PnWN4WbBREaXHFKlXpgd+eenlHhrjuMeg=; b=mdWBr9y4/saX/olRUvc4xhvE007Flur3rwcqbRmSaF5eTey17yABlFRfSfR9ghiATw AJOC/gZKvU+MLRr5O05M1EJ9NAKnBM1n4uX/ZONJKYt5cH1toXL3V4QUK/RI9BvG8UYJ NbBSwT4xPfxbkhLVao/wRHJVccIJ7DXzfaM+Sker3yC7JI2A+Ju9h448PwgbBmADMJeF CfzKPpG7L4YFuMjQB9Y48THBsUKRvxK6TnuiNctHgjdH0TlyHHMjMBFc8Si+SsJk9WeI 7QS6GVpLCLUB+sz7DCFhZxoVyp+RZ44EPT+sp1hzymaAnCEGbDCcnbbhOHtC4O5opPIO kFLA==
Received: by 10.66.86.101 with SMTP id o5mr33145322paz.15.1352478615942; Fri, 09 Nov 2012 08:30:15 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id wf8sm17938863pbc.65.2012.11.09.08.30.14 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 09 Nov 2012 08:30:15 -0800 (PST)
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <5AF341E0-FFB9-44DA-A9A5-FBF004F5F4E4@softarmor.com>
Date: Fri, 9 Nov 2012 10:30:11 -0600
To: Eric Rescorla <ekr@rtfm.com>, Cullen Jennings <fluffy@cisco.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQm2+afwp7rP4W38tGzGR8p46VPs3bEPSWW64kM9oWBAkHMtsWVVRcv7eZGZeMU3lUy3pQaX
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base issue: stringprep of password
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 16:30:18 -0000

AD comment:

Section 11.3: What character set is allowed for passwords? What if =
something is URL escaped - what's going to match? I'm sure you can copy =
from somewhere else, not quite sure what's best though.


Since we're doing passwords in a POST form, I don't know that URL =
escaping is an issue. Do we have other stringprep issues? Is there =
something we can crib from elsewhere for this spec?

--
Dean


From dean.willis@softarmor.com  Fri Nov  9 08:37:35 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A19BD21F86FC for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:37:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pPVj4fHRKLQT for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:37:30 -0800 (PST)
Received: from mail-pb0-f44.google.com (mail-pb0-f44.google.com [209.85.160.44]) by ietfa.amsl.com (Postfix) with ESMTP id 68C3121F86D0 for <p2psip@ietf.org>; Fri,  9 Nov 2012 08:37:30 -0800 (PST)
Received: by mail-pb0-f44.google.com with SMTP id ro8so3140162pbb.31 for <p2psip@ietf.org>; Fri, 09 Nov 2012 08:37:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer; bh=nG+3OEpi3BlYPy0us38EIPFzhAS+xL5VGUQQ8f+xhGE=; b=OzN/NM7d8skSZxxKNbNbsukcmcrQwKhFjXG+CxU5lZH7siqVkp5xZopNipw5JLry1p Pz/tv02wtNoMuUW7MwmqU+ag4X1Obz46Ta7YIFqo187G+PY/LlzY3pen4zObkfRV4ovz XdpSVdPt20sism6yCRDMUpBvzoBE9bJ/GWqzA=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer:x-gm-message-state; bh=nG+3OEpi3BlYPy0us38EIPFzhAS+xL5VGUQQ8f+xhGE=; b=GWOSo2NlvAx+NB++ttdMsEcdeoc2uZB1n6mPtbE4cmPZgAdddVw42A2fHSE3QrlN3W GjcXSD6vx39q5pUOmApXQGqdHTzmJCBqdIjItEm28NhMra5b2aIJkdiWK2ekZOi9f3fc fXzDOz9byJfZnMlR2uL1yTMiX4hVCMQ3spjgX67aKk6vUbGxk+DNyIFJvcS7KnZsJZm/ BaWp1/vk/A95cZQLNUPzBj79Y5frNYVoKJ8h9+RQonJWAvaU7smXhwmVwd0iUqKt8Wha 3MQUatU5VVn7O3BpTkqKDHpPo1JHU6wCRK3frrl35Gg1n9xmxUjoKPrXiTSpdeQnq0va n0FQ==
Received: by 10.66.87.226 with SMTP id bb2mr33113786pab.57.1352479050231; Fri, 09 Nov 2012 08:37:30 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id j4sm18178392pax.31.2012.11.09.08.37.28 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 09 Nov 2012 08:37:29 -0800 (PST)
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <8E9109CB-EC93-4788-9172-8767C1AA9DB5@softarmor.com>
Date: Fri, 9 Nov 2012 10:37:27 -0600
To: Eric Rescorla <ekr@rtfm.com>, Cullen Jennings <fluffy@cisco.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQkF6/ujaaTHF8h0eK7XnePwcwGnix7RujwByancx4ikZMqKnn6zwQPHQEiJOjSGPBEkwUxB
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base: Question on certificate renewal
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 16:37:35 -0000

AD asks:

How is node key rollover done? Do I loose all stored data? I think you =
need to make all those clear.



So, what I think we're talking about is what happens to my data when my =
certificate expires.=20

Does my NodeID change?

Is there a way to re-cert my stored data?

What exactly is the process for refreshing the data I have stored?

--
Dean


From dean.willis@softarmor.com  Fri Nov  9 08:42:20 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9C2E621F870C for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:42:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mJDvWKzH2sI6 for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:42:20 -0800 (PST)
Received: from mail-da0-f44.google.com (mail-da0-f44.google.com [209.85.210.44]) by ietfa.amsl.com (Postfix) with ESMTP id 0B3AA21F8705 for <p2psip@ietf.org>; Fri,  9 Nov 2012 08:42:20 -0800 (PST)
Received: by mail-da0-f44.google.com with SMTP id h15so1856568dan.31 for <p2psip@ietf.org>; Fri, 09 Nov 2012 08:42:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer; bh=SX/X8OghEzr/LHB6OBlfXbI26MUYijr08vc1HkWLC/c=; b=KXTTPH1vfOuiHU8PfmBL3ESAB4o4LJ9Pfvm7BvCdJueXK8QBHF4alRfYtYiJUT/XR0 vLBE6F5SSVCg07WJ7Dg8oo2IQY2Zgz4ubdAtfPPlgijicnZfoo8lje538Pdjqpd8FtJw fVZ6ZVEZhKXsQRx0+DXAVrR3nlUlORyHJqm5o=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer:x-gm-message-state; bh=SX/X8OghEzr/LHB6OBlfXbI26MUYijr08vc1HkWLC/c=; b=Ju9j5+KlXnbJ9nctigv0bGxfH4Fi0xBvXHmGXs+hmqcEYBMSK9eB/SMJiUtIkFlgwt 00wymlXPvgevaY0fm0cB+0++Lyvpb3Gp8Y51tz7XOrf4glBVe24uGALD6jV9wMG+7DCC LyW6OAWjjKsWpbGmEjdsFnckdLAVKYOBZ8UFsbWLJ365KW55a41nK/entYeo+cUyFsM4 BBFrK7yGpXWjhK5ARJQ9yk1kNKfWHXaN16gf6PKuyE3TuBtOurxdQqV5b2GN5Bi/4Hta nIwqgzXQe1AUdoV/WPOFYQy6UqiJYFM8i9Xk7YQYBARM8v1HcpsmVcmu+O6y5eQehwes g1ng==
Received: by 10.68.239.104 with SMTP id vr8mr35332848pbc.59.1352479339774; Fri, 09 Nov 2012 08:42:19 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id ot5sm425696pbb.29.2012.11.09.08.42.18 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 09 Nov 2012 08:42:19 -0800 (PST)
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <5A26AC14-04CE-4355-AA41-EAAAE238DAA4@softarmor.com>
Date: Fri, 9 Nov 2012 10:42:16 -0600
To: Cullen Jennings <fluffy@cisco.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQnB4f1pOErjZuxhCiBmpw6qAfPdUxe9lQZrWdRD8l8bvGSTH6s1fnIIa0gqH7VbB8aaAuzv
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base: Replay of JoinReq and LeaveReq
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 16:42:20 -0000

AD asks: section 6.4.2.1: What prevents/detects replay of JoinReq =
messages? If replay worked, then I could cause lots of havoc since the =
responding peer will do a bunch of Stores and Updates.


6.4.2.2 says "Because leaves may only be executed between nodes which =
are directly
   adjacent, receiving peers MUST verify that any LeaveReq they receive
   arrives from a transport channel that is bound to the Node-ID to be
   assumed by the leaving peer.)  This also prevents replay attacks
   provided that DTLS anti-replay is used.".=20


There's no such text for JoinReq and I'm not exactly sure that the rest =
of the document prevents routing of LeaveReq or JoinReq.

How do we want to handle this?=

From dean.willis@softarmor.com  Fri Nov  9 08:47:00 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E70421F860F for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:47:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OnTWWild469m for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:46:59 -0800 (PST)
Received: from mail-pa0-f44.google.com (mail-pa0-f44.google.com [209.85.220.44]) by ietfa.amsl.com (Postfix) with ESMTP id AFDF721F847F for <p2psip@ietf.org>; Fri,  9 Nov 2012 08:46:59 -0800 (PST)
Received: by mail-pa0-f44.google.com with SMTP id fb11so3109618pad.31 for <p2psip@ietf.org>; Fri, 09 Nov 2012 08:46:59 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer; bh=+5GSOJbh87AS5qz7P7g9ukJCMzbZ9bpvRb3h6urkcMQ=; b=MGfrSrneNUdRl0E/w02gyvI3UQjG0r8Xi0RZu2Y4s29Sw9SF2NO+WqrSEazUY9Rjim C0OEnsRhjpQK6QQ7osBCgrg4jESbFAlHKYrqbMY7Q3dDiKV4t7Wc+cM/SnRCqLThqBsj RdhKI+p6hG3SOWmOPeH6cP3NJYjyVhqDKfne8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer:x-gm-message-state; bh=+5GSOJbh87AS5qz7P7g9ukJCMzbZ9bpvRb3h6urkcMQ=; b=CTmSfI0BsJq+Z9Zp0wW6vWLTQ8YCtYrnLDKRQ9z0r/KVf0AZ+TaMBtpzD8YQ+cghkK 2Q1YXAzL5ilYgbay+pUU5OujpJJQMr+byEiekS3MY+0NXISVxCrtAqwenH0BmEmwllrK jFjC+71obpuk2+xCF8lwHrMkAXVW+6tINvUlsoCHfthmVszplTpQMiqsM8h/jzLkHcZY YEjhZ5do1CG177Ya4yzBBAdT3twYvVecsv+MrYE1X8wJNvKqL937DWK8qkWKBjxddKSS QP7svk1mq02LLncnBhirCdSKViYrQcrwt6gN1oh1cazaoOz9VdrQOoNWM8XMSUfI5vv6 ZfXw==
Received: by 10.68.232.2 with SMTP id tk2mr29035747pbc.92.1352479619477; Fri, 09 Nov 2012 08:46:59 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id n6sm18194795pav.18.2012.11.09.08.46.58 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 09 Nov 2012 08:46:58 -0800 (PST)
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <5CA52C99-86B9-4FE8-9AC4-077F3C48DCE6@softarmor.com>
Date: Fri, 9 Nov 2012 10:46:56 -0600
To: Eric Rescorla <ekr@rtfm.com>, Cullen Jennings <fluffy@cisco.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQnktjzxSw7f6oyMkSxWMLW+VYdvmsD+scCahUPNUUZLSQKzDYnoxdi3/LSjs61gc4AxHbvU
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 16:47:00 -0000

AD asks:

section 7.4.2.2: If the signer's cert has expired, is a signature on a =
stored value still considered valid or not? One issue is that if any =
revocation/status checking is supported then there may not be any such =
information available for expired certs. Another issue is that if you do =
consider signatures only verifiable with non-expired certs, then a lot =
can go wrong when a cert expires and its hard to fix that up. I don't =
have a good solution to offer, but maybe you have an answer?

In the current doc, 7.1 says:
   When signatures are verified, the current time MUST
   be compared to the certificate validity period.  However, it is
   permitted to have a value signed which expires after a certificate's
   validity period (though this will likely cause verification failure
   at some future time.)

I understand that some implementations flush any object for which the =
signing certificate has expired; that is, the upper TTL for an object is =
the remaining validity period for the signing certificate. This could be =
enforced on insertion, or by audit/cleanup processes.

How do we want to handle it?

--
Dean=

From dean.willis@softarmor.com  Fri Nov  9 08:53:21 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9336E21F8518 for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:53:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AXCm2UABzO1N for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 08:53:20 -0800 (PST)
Received: from mail-pa0-f44.google.com (mail-pa0-f44.google.com [209.85.220.44]) by ietfa.amsl.com (Postfix) with ESMTP id 8F60A21F8578 for <p2psip@ietf.org>; Fri,  9 Nov 2012 08:53:20 -0800 (PST)
Received: by mail-pa0-f44.google.com with SMTP id fb11so3113332pad.31 for <p2psip@ietf.org>; Fri, 09 Nov 2012 08:53:19 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer; bh=CIok6g4G16j4Ao5lc4UBXK+nteYocShz/gwo+Z5xza0=; b=MKubU9MEG3IYkn1xyNLqPyv9qE+P/0jQBsZniPudyWq7REsyfRGeRKklE7vz3SduS1 HakTkiKDswD7vKZ9KLkEeh5Ogfcx94DDarkksRh9dXwP0AadcbEkUi3gPIUjZfg0V2ru stIhrIfMOZb2HMzlJXue4vffjMAB0rLeToQ64=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:content-transfer-encoding:from:content-type:message-id:date :cc:to:mime-version:x-mailer:x-gm-message-state; bh=CIok6g4G16j4Ao5lc4UBXK+nteYocShz/gwo+Z5xza0=; b=oXbazFxyGX30XSkDtIS3dPBft4yFqI9sLrmGOdlBgMvKNB/g8dZ+EyRHub6huLsyWL tvqo8kphsBsmaYu/dSBrNSqXheUbAyoETJpvcLRRJvfdv5gFZMUjEVbx9Bq3b/3brxKT euxeqibNDmaBf4Sg0oUJ5woI/GtXEDsI049a6un0NKSVK5qcsfStWIgUzPCPWLH15z5i bPB2uOYDZxTEeEZwteLoisScT5h7Av64fDdPhWogLylrMzKPikd2dEVppHAdDffz5mKv GtXgBr2oZ7ilvoaCiNAP4tLJZugnLUXstwDe6rghj2jotJ876xkHiFdCvHOYEDmvW2EZ R7Pw==
Received: by 10.68.240.233 with SMTP id wd9mr10090377pbc.127.1352479999819; Fri, 09 Nov 2012 08:53:19 -0800 (PST)
Received: from dhcp-5098.meeting.ietf.org (dhcp-5098.meeting.ietf.org. [130.129.80.152]) by mx.google.com with ESMTPS id t1sm18204701paw.11.2012.11.09.08.53.18 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 09 Nov 2012 08:53:19 -0800 (PST)
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: text/plain; charset=us-ascii
Message-Id: <CCE0A213-AFA9-4822-8958-DE120F00BA0B@softarmor.com>
Date: Fri, 9 Nov 2012 10:53:16 -0600
To: Cullen Jennings <fluffy@cisco.com>, Eric Rescorla <ekr@rtfm.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQnDqPg2ATDvdWrk6Ihemi0+KHkR/LodmSUlmBLZY1gFQ/+TypLIWOfRxlxl+rFfIgViU3Sv
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base: Domain component of TFC 822 usernames
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 16:53:22 -0000

AD asks:

(16) section 11.3: might need to warn against dodgy username values,e.g. =
containing a null character or whatever. I think you need some more =
rules there to end up with a safe rfc822name in the cert. (Or else have =
an argument that that's not a problem for RELOAD - it has been a problem =
elsewhere.) Also, does the enrollment server choose the domain component =
of the rfc822 name or may that be supplied by the client?



 First question I think we can address by an edit: change 11.3 says =
:"Enrollment servers SHOULD take care to only allow legal characters in =
the name (e.g., no embedded NULs), rather than simply accepting any name =
provided by the user." We can make the SHOULD a MUST and add reference =
to RFC 4013. =20

The second question was raised at the meeting in IETF 85:

Does the enrollment server choose the domain component of the rfc822 =
name or may that be supplied by the client?


This is the same question as:

Is the domain part of the username the same as the domain name of the =
overlay, or can the overlay support usernames in multiple domains?

This has a big impact on some use cases, such as having multiple =
enterprise-specific name spaces in a shared overlay.

For example, if alice@example.com and alice@example.org are two =
different people and neither wants to change their username part, can =
one overlay suit them both?

--
Dean


From buford@avaya.com  Fri Nov  9 10:10:06 2012
Return-Path: <buford@avaya.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B4A3821F8771 for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 10:10:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y6ZaSIEcExGK for <p2psip@ietfa.amsl.com>; Fri,  9 Nov 2012 10:10:06 -0800 (PST)
Received: from de307622-de-outbound.net.avaya.com (de307622-de-outbound.net.avaya.com [198.152.71.100]) by ietfa.amsl.com (Postfix) with ESMTP id E569521F85ED for <p2psip@ietf.org>; Fri,  9 Nov 2012 10:10:05 -0800 (PST)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Av8EAJlGnVDGmAcF/2dsb2JhbABEw0KBCIIeAQEBAQMBAQEPKDQLDAYBFQQEAQEfCS4LFAkJAQQBDQUIGodaDgugdZkAhBAEjBSFaWEDiFqTLoo2gw0
X-IronPort-AV: E=Sophos;i="4.80,746,1344225600"; d="scan'208";a="331974550"
Received: from unknown (HELO co300216-co-erhwest.avaya.com) ([198.152.7.5]) by de307622-de-outbound.net.avaya.com with ESMTP; 09 Nov 2012 13:04:53 -0500
Received: from unknown (HELO DC-US1HCEX4.global.avaya.com) ([135.11.52.35]) by co300216-co-erhwest-out.avaya.com with ESMTP; 09 Nov 2012 13:07:47 -0500
Received: from DC-US1MBEX5.global.avaya.com ([169.254.2.145]) by DC-US1HCEX4.global.avaya.com ([135.11.52.35]) with mapi; Fri, 9 Nov 2012 13:09:50 -0500
From: "Buford, John F (John)" <buford@avaya.com>
To: Dean Willis <dean.willis@softarmor.com>, "p2psip@ietf.org" <p2psip@ietf.org>
Date: Fri, 9 Nov 2012 13:10:30 -0500
Thread-Topic: p2psip-base sec 6.3.3 
Thread-Index: Ac2+orWjpMw9d5tgTA+Bes3zlQOsPQ==
Message-ID: <ACCC07BD69AAD84B9383C920F3EBD20343563FF4F8@DC-US1MBEX5.global.avaya.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: [P2PSIP] p2psip-base sec 6.3.3
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2012 18:10:06 -0000

Section 6.3.3

"MessageExtension" is referred to in MessageContents struct as "MessageExte=
nsions".

Section 6.3.3.1

Error codes "Error_Exp_A" and "Error_Exp_B" are defined in the table in 14.=
9 but are not listed
in section 6.3.3.1. =20

-----Original Message-----
From: p2psip-bounces@ietf.org [mailto:p2psip-bounces@ietf.org] On Behalf Of=
 Dean Willis
Sent: Thursday, November 08, 2012 5:07 PM
To: p2psip@ietf.org
Subject: [P2PSIP] Live tracker for known AD issues on p2psip-base

I'm working from a GDocs spreadsheet at:

https://docs.google.com/spreadsheet/ccc?key=3D0AnloAbucfY99dHNWTHZXU1JndFlE=
TjE2UzkyNG1ybGc

We've classified 130 or so of the 188 comments received. Most are minor edi=
ts. Several need to be taken to the list and authors for further thought. I=
'll be sending more on those as we go.

--
Dean
_______________________________________________
P2PSIP mailing list
P2PSIP@ietf.org
https://www.ietf.org/mailman/listinfo/p2psip

From cjbc@it.uc3m.es  Mon Nov 12 09:23:13 2012
Return-Path: <cjbc@it.uc3m.es>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C5B521F8753 for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 09:23:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.299
X-Spam-Level: 
X-Spam-Status: No, score=-6.299 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4qXo2PB+CHhN for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 09:23:12 -0800 (PST)
Received: from smtp02.uc3m.es (smtp02.uc3m.es [163.117.176.132]) by ietfa.amsl.com (Postfix) with ESMTP id 6915121F8751 for <p2psip@ietf.org>; Mon, 12 Nov 2012 09:23:12 -0800 (PST)
X-uc3m-safe: yes
Received: from [163.117.139.247] (unknown [163.117.139.247]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: cjbc@smtp02.uc3m.es) by smtp02.uc3m.es (Postfix) with ESMTPSA id 19EE8894727 for <p2psip@ietf.org>; Mon, 12 Nov 2012 18:23:11 +0100 (CET)
Message-ID: <1352740991.16511.116.camel@acorde.it.uc3m.es>
From: Carlos =?ISO-8859-1?Q?Jes=FAs?= Bernardos Cano <cjbc@it.uc3m.es>
To: P2PSIP WG <p2psip@ietf.org>
Date: Mon, 12 Nov 2012 18:23:11 +0100
Organization: Universidad Carlos III de Madrid
Content-Type: text/plain; charset="UTF-8"
X-Mailer: Evolution 3.4.3-1 
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit
X-TM-AS-Product-Ver: IMSS-7.1.0.1224-6.8.0.1017-19358.000
X-TM-AS-Result: No--1.738-7.0-31-1
X-imss-scan-details: No--1.738-7.0-31-1
Subject: [P2PSIP] Draft of meeting minutes uploaded
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: cjbc@it.uc3m.es
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Nov 2012 17:23:13 -0000

Hi,

A draft of the minutes is available:

http://www.ietf.org/proceedings/85/minutes/minutes-85-p2psip

Many thanks Jean for providing the minutes.

Please provide your feedback by the end of next week.

Thanks,

Brian & Carlos




From petithug@acm.org  Mon Nov 12 10:03:53 2012
Return-Path: <petithug@acm.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3644421F86F3 for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 10:03:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.6
X-Spam-Level: 
X-Spam-Status: No, score=-102.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2PJx63l692pG for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 10:03:52 -0800 (PST)
Received: from implementers.org (implementers.org [IPv6:2604:3400:dc1:41:216:3eff:fe5b:8240]) by ietfa.amsl.com (Postfix) with ESMTP id 996E821F86EC for <p2psip@ietf.org>; Mon, 12 Nov 2012 10:03:51 -0800 (PST)
Received: from [IPv6:2601:9:4b80:32:88c8:3b17:4649:60a8] (unknown [IPv6:2601:9:4b80:32:88c8:3b17:4649:60a8]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (Client CN "Marc Petit-Huguenin", Issuer "implementers.org" (verified OK)) by implementers.org (Postfix) with ESMTPS id 5880D20483; Mon, 12 Nov 2012 18:03:49 +0000 (UTC)
Message-ID: <50A13A04.4090602@acm.org>
Date: Mon, 12 Nov 2012 10:03:48 -0800
From: Marc Petit-Huguenin <petithug@acm.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.10) Gecko/20121027 Icedove/10.0.10
MIME-Version: 1.0
To: cjbc@it.uc3m.es
References: <1352740991.16511.116.camel@acorde.it.uc3m.es>
In-Reply-To: <1352740991.16511.116.camel@acorde.it.uc3m.es>
X-Enigmail-Version: 1.4.1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Cc: P2PSIP WG <p2psip@ietf.org>
Subject: Re: [P2PSIP] Draft of meeting minutes uploaded
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Nov 2012 18:03:53 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 11/12/2012 09:23 AM, Carlos Jesús Bernardos Cano wrote:
> Hi,
> 
> A draft of the minutes is available:
> 
> http://www.ietf.org/proceedings/85/minutes/minutes-85-p2psip
> 
> Many thanks Jean for providing the minutes.
> 
> Please provide your feedback by the end of next week.
> 

The beginning is a bit mangled because of UTF-8 -> ISO-8859-1 conversion, so I
would suggest to convert the whole text to US-ASCII.

The content matches my recollection of the meeting - good job by the
note-taker(s).

- -- 
Marc Petit-Huguenin
Email: marc@petit-huguenin.org
Blog: http://blog.marc.petit-huguenin.org
Profile: http://www.linkedin.com/in/petithug
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJQoToDAAoJECnERZXWan7EWEgQALiIy6cC4tUXMMyU+av6RkLX
mMcRY8YBadUoW/yI7o56Tp+eHFtACJnxbttiovsDlgmZUU41iDrXVVrN2GSXAjeo
RCl40Cmv4tQoN/uZoTjOMXJR2GjhGlYXcUbOxgEgvvb27t1+fp40bs4VE9s22s00
g2z7oLIAcB6m/+BzTflobloThFwuZzMJdlpkNAWR51ReEWUIdv/+z4zn4MxaSdOi
7p3ih092hYmLOCrVm8p0gTSUL5yP6T60DGrvKxjvTgu01fLLMu9fJHNh2gsDDXr0
rs6X9kmh88buk67/pgrXDY4KKP4dseMmrJJ/NWRZgurWgJDTISN8/PoIjQFlHDw1
/rtOQVO6G0MUc8094hbTnzCHuAwLbnkXMCxebZp+IVbZsyOFe0nZHMKWJrgRxjh8
IjTcjcIzhMbQFdwYCbHZ8/Ohjx3G+bAccokekq5OJf+Jv+ybbCO/NOCxiD/x4wkB
vKC9THfxJ7KFmmtGT/H6Rr2Ni/crdXCUaYlICcz3eqvsJqBCIpGaoMYREjWSNysC
K1TqlKjTS1JkCRZTyFQMFop/wFL3m9DF306TkkyUfbk7NDwuOoJOMLmuP17D8yjd
i9wkUF9/+ECJRWhCgJlJ6tjoH3ajuf2ja6sI0Oz+K3Fb/0Sa0crlNKZtEnIQjmWh
WV8co4IHxqvL8OSBQbq8
=UX9y
-----END PGP SIGNATURE-----

From cjbc@it.uc3m.es  Mon Nov 12 10:22:20 2012
Return-Path: <cjbc@it.uc3m.es>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61CB221F86C1 for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 10:22:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.999
X-Spam-Level: 
X-Spam-Status: No, score=-5.999 tagged_above=-999 required=5 tests=[AWL=-0.300, BAYES_00=-2.599, J_CHICKENPOX_21=0.6, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KjwcwrZYfthI for <p2psip@ietfa.amsl.com>; Mon, 12 Nov 2012 10:22:19 -0800 (PST)
Received: from smtp01.uc3m.es (smtp01.uc3m.es [163.117.176.131]) by ietfa.amsl.com (Postfix) with ESMTP id 81FF021F86D3 for <p2psip@ietf.org>; Mon, 12 Nov 2012 10:22:19 -0800 (PST)
X-uc3m-safe: yes
Received: from [163.117.139.247] (unknown [163.117.139.247]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: cjbc@smtp01.uc3m.es) by smtp01.uc3m.es (Postfix) with ESMTPSA id 40FF6C4007D; Mon, 12 Nov 2012 19:22:17 +0100 (CET)
Message-ID: <1352744536.16511.130.camel@acorde.it.uc3m.es>
From: Carlos =?ISO-8859-1?Q?Jes=FAs?= Bernardos Cano <cjbc@it.uc3m.es>
To: Marc Petit-Huguenin <petithug@acm.org>
Date: Mon, 12 Nov 2012 19:22:16 +0100
In-Reply-To: <50A13A04.4090602@acm.org>
References: <1352740991.16511.116.camel@acorde.it.uc3m.es> <50A13A04.4090602@acm.org>
Organization: Universidad Carlos III de Madrid
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature";  boundary="=-qw6nltLyQQb1KwhEKs4y"
X-Mailer: Evolution 3.4.3-1 
Mime-Version: 1.0
X-TM-AS-Product-Ver: IMSS-7.1.0.1224-6.8.0.1017-19358.001
X-TM-AS-Result: No--13.653-7.0-31-1
X-imss-scan-details: No--13.653-7.0-31-1
Cc: P2PSIP WG <p2psip@ietf.org>
Subject: Re: [P2PSIP] Draft of meeting minutes uploaded
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: cjbc@it.uc3m.es
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 12 Nov 2012 18:22:20 -0000

--=-qw6nltLyQQb1KwhEKs4y
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Marc,

Thanks for your comments. New version updated. It should solve the UTF-8
issues.

Thanks,

Carlos

On Mon, 2012-11-12 at 10:03 -0800, Marc Petit-Huguenin wrote:
> On 11/12/2012 09:23 AM, Carlos Jes=C3=BAs Bernardos Cano wrote:
> > Hi,
> >=20
> > A draft of the minutes is available:
> >=20
> > http://www.ietf.org/proceedings/85/minutes/minutes-85-p2psip
> >=20
> > Many thanks Jean for providing the minutes.
> >=20
> > Please provide your feedback by the end of next week.
> >=20
>=20
> The beginning is a bit mangled because of UTF-8 -> ISO-8859-1 conversion,=
 so I
> would suggest to convert the whole text to US-ASCII.
>=20
> The content matches my recollection of the meeting - good job by the
> note-taker(s).
>=20

--=20
Carlos Jes=C3=BAs Bernardos Cano  http://www.netcom.it.uc3m.es/
GPG FP: D29B 0A6A 639A A561 93CA  4D55 35DC BA4D D170 4F67

--=-qw6nltLyQQb1KwhEKs4y
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEABECAAYFAlChPlgACgkQNdy6TdFwT2eBAgCdEwEh+14fOzCoP2QiiRmvXAjV
zGQAnjtUJ68jQdEuB1yaJcjJeW4BozAf
=aX2D
-----END PGP SIGNATURE-----

--=-qw6nltLyQQb1KwhEKs4y--


From petithug@acm.org  Tue Nov 13 11:09:09 2012
Return-Path: <petithug@acm.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 592A421F86B0 for <p2psip@ietfa.amsl.com>; Tue, 13 Nov 2012 11:09:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.543
X-Spam-Level: 
X-Spam-Status: No, score=-102.543 tagged_above=-999 required=5 tests=[AWL=0.057, BAYES_00=-2.599, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rYz6XM+9bt-H for <p2psip@ietfa.amsl.com>; Tue, 13 Nov 2012 11:09:08 -0800 (PST)
Received: from implementers.org (implementers.org [IPv6:2604:3400:dc1:41:216:3eff:fe5b:8240]) by ietfa.amsl.com (Postfix) with ESMTP id 9404F21F868F for <p2psip@ietf.org>; Tue, 13 Nov 2012 11:09:08 -0800 (PST)
Received: from [IPv6:2601:9:4b80:32:2427:e203:f5ae:88d9] (unknown [IPv6:2601:9:4b80:32:2427:e203:f5ae:88d9]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (Client CN "Marc Petit-Huguenin", Issuer "implementers.org" (verified OK)) by implementers.org (Postfix) with ESMTPS id D202220483; Tue, 13 Nov 2012 19:09:06 +0000 (UTC)
Message-ID: <50A29AD1.8070502@acm.org>
Date: Tue, 13 Nov 2012 11:09:05 -0800
From: Marc Petit-Huguenin <petithug@acm.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.10) Gecko/20121027 Icedove/10.0.10
MIME-Version: 1.0
To: "Buford, John F (John)" <buford@avaya.com>
References: <ACCC07BD69AAD84B9383C920F3EBD20343563FF4F8@DC-US1MBEX5.global.avaya.com>
In-Reply-To: <ACCC07BD69AAD84B9383C920F3EBD20343563FF4F8@DC-US1MBEX5.global.avaya.com>
X-Enigmail-Version: 1.4.1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Cc: "p2psip@ietf.org" <p2psip@ietf.org>, Dean Willis <dean.willis@softarmor.com>
Subject: Re: [P2PSIP] p2psip-base sec 6.3.3
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Nov 2012 19:09:09 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi John,

On 11/09/2012 10:10 AM, Buford, John F (John) wrote:
> Section 6.3.3
> 
> "MessageExtension" is referred to in MessageContents struct as
> "MessageExtensions".

I believe this is already fixed in -23 (#189 in spreadsheet).

> 
> Section 6.3.3.1
> 
> Error codes "Error_Exp_A" and "Error_Exp_B" are defined in the table in
> 14.9 but are not listed in section 6.3.3.1.

Added in spreadsheet as #190.

Thanks.

- -- 
Marc Petit-Huguenin
Email: marc@petit-huguenin.org
Blog: http://blog.marc.petit-huguenin.org
Profile: http://www.linkedin.com/in/petithug
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJQoprOAAoJECnERZXWan7EdwcP/3DcANt2hKDE0ZUkXIrb157V
rVMqfMk9BC1xBtM7z7fsOR3liXbS9W76cuDB51KcUt3zUxZxCoXzrSH8iN2yPd3a
+ovDxUcUMvy1/yDRWvCv1a5dgJIgw0tVKQ1Keaz9F+Nyhqiq4D0/YN/jUYa5vEp/
VUGIeGzPeH9kcmDF0gRLiNqGA8UTk3ZR7QzQ5EhiJxGgSxfwm+fPg9Zg2fAzA+Na
MMXzBQpXx7arAHbdlnqo3hwArwDw0lBRGKJ/kQccjNCuMoZB1Tlo0Gr56RlbYaNC
bSCbi5XMm2HeVlhSdHJ6rCJKvoXrY5cEPJIQ80HKda+uSLQBZArg3LKTULb+Yb6G
xBEtlvUp7c/f5U+uUwzU6BtJNQjyQ6W/05HnN8UuFuJDv/3KzYzhLTlSIYsjJd5f
N8UoKM6l4rj+SYFOZkXIXyhftDlseTVxhf+q+Yx0FMxO/U2I6RgUjl3gmrD3XDbV
LcFtpjN6h+xMOePF49CCDuiM1QWPDeSSU8JlphkIXIijMUDL8wZty9wz4YMfVLvw
v5J6XlyEJh6EOZ79pJzVG4SqCRtKrKrxbag+GARtSepgLBC+PA7lG5hY3wb+2ODb
mxjdO5qgR1m2UWeyUs/blGOn40IcRIrXWJKmBLDBJVMh6vvjn48JdxwAgZBp34l0
qzlhzrnuCwa+ZMdI4AML
=frBD
-----END PGP SIGNATURE-----

From dean.willis@softarmor.com  Wed Nov 14 11:44:45 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4D1B821F87E0 for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 11:44:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sOSpp5aLfcUJ for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 11:44:44 -0800 (PST)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 8D1F221F87DC for <p2psip@ietf.org>; Wed, 14 Nov 2012 11:44:44 -0800 (PST)
Received: by mail-ob0-f172.google.com with SMTP id ef5so914711obb.31 for <p2psip@ietf.org>; Wed, 14 Nov 2012 11:44:44 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer; bh=LvDOxKVIwFOVlWeAaNHQOEpGI8y3QwW3wc5H+f2Yv2k=; b=LU534FE/Um5kjp2DQSDLm1z+5H+axAp96w5Fa6u/Xe9HFiu/3o01gdyZCRdxequWHT 0blsKhUlnNY9fc7oHi3JkDmsGLnKtbpYkxCwdVhMIBEXkH1noSCi+e7U/QbFrx8sFZ04 YQAMG2mkBOtv4smijMFtLWdOidSy+kblxlnk8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer :x-gm-message-state; bh=LvDOxKVIwFOVlWeAaNHQOEpGI8y3QwW3wc5H+f2Yv2k=; b=loHTRWlcT9DH4eLjpfVwkHv/ByyMUfMIDmZyUZMmjffy5wGSdTDcMEKl3/QRLQpTJB ND1AgtEAzSWWjupB3+xdhpH4mjztI8kuzQgpxSoCrY4kNh4cibh3GDzhcUlfvAi6nghy +2X5qVpJQTkePYdcsS06VWumnZBBQuUepWG38ktalTqgittat41/S1MnKHvq1mdhJslh IOsdg8diTroM5xI+S9wlvCjIsF+t+FfYxgd/n37aeoPbWoQxOrgCrZhLFV7BhTx6yd0t X6iyIBEAnYRckw+jhrkKDtViPOT3bp/9CcvjpR9XXC7MfT1dWJclwipMe9sleS5Yu1qu y2lQ==
Received: by 10.182.95.234 with SMTP id dn10mr21648228obb.97.1352922283945; Wed, 14 Nov 2012 11:44:43 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id v3sm10762210oee.0.2012.11.14.11.44.42 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 14 Nov 2012 11:44:43 -0800 (PST)
References: <5AF341E0-FFB9-44DA-A9A5-FBF004F5F4E4@softarmor.com>
In-Reply-To: <5AF341E0-FFB9-44DA-A9A5-FBF004F5F4E4@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <7FBFACAB-BEC8-471B-8CDB-76E6483F4575@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Wed, 14 Nov 2012 13:35:40 -0600
To: Dean Willis <dean.willis@softarmor.com>
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQkM4cKyrJcbYXWDX/4O1/pJ3JHkMn9OwylCWZz3PaazNwgPbcFRUGfvsk8TBhyIZhHl5kxw
Cc: Cullen Jennings <fluffy@cisco.com>, p2psip@ietf.org
Subject: Re: [P2PSIP] RELOAD Base issue: stringprep of password
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Nov 2012 19:44:45 -0000

Cullen, Ekr and I discussed this today, and Cullen solicited input from =
Peter Saint-Andre


Peter says:=20

As to the charset issue, it seems safest to specify that the charset =
must be UTF-8 (we don't want to end up with something like =
charset=3Dwindows-1250 as in Section 4.5 of RFC 2388).=20

As to preparation of usernames and passwords, it seems safest right now =
to say that these strings shall be prepared in accordance with SASLprep =
(RFC 4013) prior to comparison -- see RFC 4616 for text you could =
borrow.

[Eventually, perhaps even relatively soon in "RELOAD years", RFC 4013 =
will be obsoleted by draft-melnikov-precis-saslprepbis; however, you =
might prefer not to gate RELOAD on output from the PRECIS WG.]



On Nov 9, 2012, at 10:30 AM, Dean Willis wrote:

>=20
> AD comment:
>=20
> Section 11.3: What character set is allowed for passwords? What if =
something is URL escaped - what's going to match? I'm sure you can copy =
from somewhere else, not quite sure what's best though.
>=20
>=20
> Since we're doing passwords in a POST form, I don't know that URL =
escaping is an issue. Do we have other stringprep issues? Is there =
something we can crib from elsewhere for this spec?
>=20
> --
> Dean
>=20


From dean.willis@softarmor.com  Wed Nov 14 14:44:28 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 198F121F884D for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:44:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jiaEqupjLbs7 for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:44:27 -0800 (PST)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 1DED221F8877 for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:44:26 -0800 (PST)
Received: by mail-ob0-f172.google.com with SMTP id ef5so1094525obb.31 for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:44:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer; bh=DECFPRuZMly7Vad4XgD4zKAULhZl8FSm06dTfhP9z1k=; b=YZubfrWSsv6nXdDTGrupTFM6hgVhVoFiw7h0q0mJJ0D9lniGhZai6AaYCc4I/gvH/B uPPG6dtRz/5CUZvvXhzW5wGhV+CqHka131RSHjzv/yvGra/Tqq+Md0EKqhdz1pZtz/tz lKc0J5zMJUlg9B92e4/8xLWYRDpK6ghmT1vH0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer :x-gm-message-state; bh=DECFPRuZMly7Vad4XgD4zKAULhZl8FSm06dTfhP9z1k=; b=DYCZ9igv0lXscBSL8e9eSN+DFzHsPPMUrMujUeRhYCMx6yHls9upAO8h6R9jmdmiNK xuteGGvbe3+RRNAGFnws8iiBxYxt5k4tzkFI7K3d/IJ5uarrs5IqPWUDpFGbqN9/AxcM Hy4hU2yaCyPgtZAIZ/hln45urOK+1uhJaxFD1XjLDg/QROslvGwVotlBbEAqdJ4DySc/ ViojUHm7mY5iJQej57oxS2ZlpCQEF+iP/IXwXZ5eXlfZyrhBEZmBEFPhex0esddmUAji vXW6DIY11Cf5lU+WW2RBFLxXF1sT8W1cbwn3V9xEFt9mYsjqCQ5rMXXijjpApyUaITCo Xekw==
Received: by 10.182.18.142 with SMTP id w14mr22628647obd.65.1352933066617; Wed, 14 Nov 2012 14:44:26 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id s5sm14160277obo.10.2012.11.14.14.44.25 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 14 Nov 2012 14:44:26 -0800 (PST)
References: <8E9109CB-EC93-4788-9172-8767C1AA9DB5@softarmor.com>
In-Reply-To: <8E9109CB-EC93-4788-9172-8767C1AA9DB5@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <800552DE-B535-4C7C-9945-F421D3779C9A@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Wed, 14 Nov 2012 16:44:24 -0600
To: p2psip@ietf.org
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQlMj+ylLlKoO04f9bRcIb+4PvIpZwh7oxB7ocoPOHOIcpxYwBik6nFsbWg9JOI6E+PMRvKn
Cc: Cullen Jennings <fluffy@cisco.com>
Subject: Re: [P2PSIP] RELOAD Base: Question on certificate renewal
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Nov 2012 22:44:28 -0000

On Nov 9, 2012, at 10:37 AM, Dean Willis wrote:

> AD asks:
>=20
> How is node key rollover done? Do I loose all stored data? I think you =
need to make all those clear.
>=20
>=20
>=20
> So, what I think we're talking about is what happens to my data when =
my certificate expires.=20
>=20
> Does my NodeID change?
>=20
> Is there a way to re-cert my stored data?
>=20
> What exactly is the process for refreshing the data I have stored?
>=20
> --
> Dean
>=20


I met with Cullen and EKR today, and here's what I think we have:

If the NodeID cert expires, you lose all data stored with that NodeID. =
If we want to invent a "recertification" technique (Marc suggested that =
the CA can issue a new cert with the same NodeID) we can do that in a =
separate document.

We will need to add a clarifying sentence to the draft.

--
Dean=

From dean.willis@softarmor.com  Wed Nov 14 14:46:29 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C43721F88B1 for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:46:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hV6XYLiiMxu8 for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:46:29 -0800 (PST)
Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) by ietfa.amsl.com (Postfix) with ESMTP id B1E3221F889D for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:46:28 -0800 (PST)
Received: by mail-oa0-f44.google.com with SMTP id n5so1102464oag.31 for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:46:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer; bh=JLI9iyulOo98VAxf+lHIv9GXdsQ6NNU6Hd6kRBHkFV8=; b=Mt6z6NX4WuXUUI6+7Krw6p+esuPS+gFyk0TlYiLoqOy7NV1uBaPaSm0hx9XCBcgQzV THrLalMa9mEnh/OVEZO/Cjacfn05qTPKaEZPgQ3iZEWcGSpA3qZu78llNoodBUkWKO2X 4UYiK59RTocQPtbTakCMx1OWpztCrr42KAo/0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer :x-gm-message-state; bh=JLI9iyulOo98VAxf+lHIv9GXdsQ6NNU6Hd6kRBHkFV8=; b=lkYLdaYyhkOwGfmL/ci7zUezhmds6YPBWU5oTPeGf0wJMFFW7GDeS2DVNwUSnrkBgV DsSacs5RMnE8pOnb7K3ibL0p9ni3jn2cyeKbLT0eSqSr/skIkODsJAdL3YwpHsMmP9G+ 8bY26WY5lscGlzAzITIsLSuGWHlNf2rDbheAuXbb4D+N9HNt0Alokvj8+22FD0EdW5Ap kRtuxWW9ltl23TmIgM/dsE5mR4GRO99g9mk5TmvlY7+WWMqRI8y3Q5/FzYen7g+FdEfL kja3LJKaWUQ2lT0cNqBBj6yKhelZf0tDfGgSenlXOHO4ixslFF7oPrUpdHdIVodJ3V0I ynqg==
Received: by 10.60.11.137 with SMTP id q9mr3895008oeb.141.1352933188292; Wed, 14 Nov 2012 14:46:28 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id zy9sm11097503oeb.4.2012.11.14.14.46.27 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 14 Nov 2012 14:46:27 -0800 (PST)
References: <5A26AC14-04CE-4355-AA41-EAAAE238DAA4@softarmor.com>
In-Reply-To: <5A26AC14-04CE-4355-AA41-EAAAE238DAA4@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <5C2F4EC0-7527-4F44-B925-5F681CB4A0AC@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Wed, 14 Nov 2012 16:46:26 -0600
To: p2psip@ietf.org
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQl7NBemw67/ES5OCGusnmOTrfic0bu5BEF0dyhV811UiJFoXHWzrE4cJEPkNMR1hYS1LNzq
Cc: Cullen Jennings <fluffy@cisco.com>
Subject: Re: [P2PSIP] RELOAD Base: Replay of JoinReq and LeaveReq
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Nov 2012 22:46:29 -0000

On Nov 9, 2012, at 10:42 AM, Dean Willis wrote:

> AD asks: section 6.4.2.1: What prevents/detects replay of JoinReq =
messages? If replay worked, then I could cause lots of havoc since the =
responding peer will do a bunch of Stores and Updates.
>=20
>=20
> 6.4.2.2 says "Because leaves may only be executed between nodes which =
are directly
>   adjacent, receiving peers MUST verify that any LeaveReq they receive
>   arrives from a transport channel that is bound to the Node-ID to be
>   assumed by the leaving peer.)  This also prevents replay attacks
>   provided that DTLS anti-replay is used.".=20
>=20
>=20
> There's no such text for JoinReq and I'm not exactly sure that the =
rest of the document prevents routing of LeaveReq or JoinReq.
>=20
> How do we want to handle this?


I met with Cullen and EKR today on this.

The document DOES have text for JoinReq. I wlll review the document for =
other incidental mentions of routing of LeaveReq and JoinReq and if I =
find any, will take steps to fix them. If you are aware of any such =
text, please point it out to me.

--
Dean
=20=

From dean.willis@softarmor.com  Wed Nov 14 14:48:41 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DB4121F88A8 for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:48:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X2+9H-ZGkGuU for <p2psip@ietfa.amsl.com>; Wed, 14 Nov 2012 14:48:41 -0800 (PST)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 11E8E21F889D for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:48:41 -0800 (PST)
Received: by mail-ob0-f172.google.com with SMTP id ef5so1098654obb.31 for <p2psip@ietf.org>; Wed, 14 Nov 2012 14:48:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer; bh=odvJvIWxOUDJiBbHhNvV8A/F/Bt2pb+S3QkLMjkC8xI=; b=FGmg26aqObhe5Mctho12JvzPive3LFPp3YTevqXLKTNvcktiRNVVR1tpEYeosnb/CW 8VViUXMv9uOp+ZjGLPqZzYGWcD4Zr3kRdya6EM8nSfQbrmAxIV4DTU8ltPta+nPhtM2O q+ci95tCQD2GqZD+TcKwkq+sblj1Fuk2mhhLg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:cc:from:subject:date:to:x-mailer :x-gm-message-state; bh=odvJvIWxOUDJiBbHhNvV8A/F/Bt2pb+S3QkLMjkC8xI=; b=KUvKwK6AWSNa5PsqsZY/WfA4qqP/Oib2BrTAsQQoWyWmKTMYJMJ1j7RL/SJxpHnKEC X3CBTmr9ec7CYIzhxQR9EGnysTX+y9OZVHlL9RUAJ0hns0P/1qeLoAAD+ZvZ1QhWOrcw yWmp/up2CIpWXHe2xJxAcutPZo4AUkIy3TkRmizSQSx8TIwCMpvBPs8LbxAd+yqjZfff rdyyoxiu/UFy0eij/uIMfAm0xk4mkvPTH6WngDIWia+WqnaIP5JWDBlWGbaPpY6bIMjL qtz8BG2XgWlfb25zea0G0wItrJhUE2j5RjlhSw/6fKKB4hkZ1y9eqWQ80CRxDyxX+/Vp Yqjg==
Received: by 10.60.30.100 with SMTP id r4mr22121609oeh.121.1352933320624; Wed, 14 Nov 2012 14:48:40 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id 10sm11086065oeg.11.2012.11.14.14.48.39 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 14 Nov 2012 14:48:40 -0800 (PST)
References: <5CA52C99-86B9-4FE8-9AC4-077F3C48DCE6@softarmor.com>
In-Reply-To: <5CA52C99-86B9-4FE8-9AC4-077F3C48DCE6@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <0D27E951-A0AF-4DFD-BE16-5C7F36BEADA5@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Wed, 14 Nov 2012 16:48:38 -0600
To: Dean Willis <dean.willis@softarmor.com>
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQk0JsijjiaEz3ah8XNW0NHnO76WB9ErxZfviB+KmhJkVn+ObR9mwDFgtBJ3v6KwfZLZFxQf
Cc: Cullen Jennings <fluffy@cisco.com>, p2psip@ietf.org
Subject: Re: [P2PSIP] RELOAD Base cert expiry
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Nov 2012 22:48:41 -0000

On Nov 9, 2012, at 10:46 AM, Dean Willis wrote:

> AD asks:
>=20
> section 7.4.2.2: If the signer's cert has expired, is a signature on a =
stored value still considered valid or not? One issue is that if any =
revocation/status checking is supported then there may not be any such =
information available for expired certs. Another issue is that if you do =
consider signatures only verifiable with non-expired certs, then a lot =
can go wrong when a cert expires and its hard to fix that up. I don't =
have a good solution to offer, but maybe you have an answer?
>=20
> In the current doc, 7.1 says:
>   When signatures are verified, the current time MUST
>   be compared to the certificate validity period.  However, it is
>   permitted to have a value signed which expires after a certificate's
>   validity period (though this will likely cause verification failure
>   at some future time.)
>=20
> I understand that some implementations flush any object for which the =
signing certificate has expired; that is, the upper TTL for an object is =
the remaining validity period for the signing certificate. This could be =
enforced on insertion, or by audit/cleanup processes.
>=20
> How do we want to handle it?
>=20
>=20

I met today with Cullen and EKR on this one.

We agree that we need to clarify in 7.4.2.2 that a signature from an =
expired cert is not valid, and that implementations may garbage-collect =
data signed by expired certs at their discretion. We can add a =
back-reference to the validity testing section in 7.1

--
Dean


From dean.willis@softarmor.com  Fri Nov 16 11:41:53 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7A3521F8ADD for <p2psip@ietfa.amsl.com>; Fri, 16 Nov 2012 11:41:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.299
X-Spam-Level: 
X-Spam-Status: No, score=-103.299 tagged_above=-999 required=5 tests=[AWL=-0.300, BAYES_00=-2.599, HTML_MESSAGE=0.001, J_CHICKENPOX_63=0.6, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wEASqH6A64HQ for <p2psip@ietfa.amsl.com>; Fri, 16 Nov 2012 11:41:52 -0800 (PST)
Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) by ietfa.amsl.com (Postfix) with ESMTP id BCD7621F8ADC for <p2psip@ietf.org>; Fri, 16 Nov 2012 11:41:52 -0800 (PST)
Received: by mail-oa0-f44.google.com with SMTP id n5so3360589oag.31 for <p2psip@ietf.org>; Fri, 16 Nov 2012 11:41:52 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:from:content-type:message-id:date:cc:to:mime-version :x-mailer; bh=LblKV9L6Dbjq06XLCbGytzPhRjBx+pafXY081X08tF4=; b=K/4+Vq+ZXiNnK8XJl0kdLN/eRdbdgHygQtP7Iy83YMuVM16usjTsfbonSOlPV82BDk GpAdKNIZGq5+ocdQKhVjBkYwqsbNGkknDzGMNLatJdBTl7fw63eptC/WQS2cRuh1zAf+ ujBlcX9CPNHEiILn7fIKo3qaPG+eoy+6vASU0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:from:content-type:message-id:date:cc:to:mime-version :x-mailer:x-gm-message-state; bh=LblKV9L6Dbjq06XLCbGytzPhRjBx+pafXY081X08tF4=; b=gN9Yk2obYH48nrAK221VcW57vDHF+pJobMdZLfiLsMRwsjGmDIReE+8I56kKFnPrbS G3R8SB7fpWvEGXd/oShyWVmz6GOBSOLSGDegdPK6XuWZuwUP8iippxR/8PJT7WZWZfNE Ne2+vBZ1PZA8ZSBb5r/1U21/ROTgoOQKZTLH4jI/IAYzmCP0Cj6/bFcKWqEjVnOZofbm u/Hvn6NfUs+8hkDDJTOgnnBRHjBaRv083fFnhorOt3L1h5N2MPvCYMabYn+WT63MxW2e OQMvx0wDDxyPwT/Hwun4lfQQBwY2BA6IzUA2qihYgsoxGX6nnunoXHKsn9EYG3vmC3YL ecKA==
Received: by 10.182.177.100 with SMTP id cp4mr4840667obc.71.1353094912206; Fri, 16 Nov 2012 11:41:52 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id n7sm2333837obd.16.2012.11.16.11.41.50 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 16 Nov 2012 11:41:51 -0800 (PST)
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-5--1021928446
Message-Id: <D4D0EB3D-44C3-4493-B3CA-5D248539FCCE@softarmor.com>
Date: Fri, 16 Nov 2012 13:41:49 -0600
To: Cullen Jennings <fluffy@cisco.com>, Eric Rescorla <ekr@rtfm.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQlTsPz9dOn0V/WTY4enQMRzvHuIcvG/qdfY/pqihDgXPARV8Zi2cPcf9uUzeDobDYkfEUz+
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD Base: Reference to Certificates
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Nov 2012 19:41:53 -0000

--Apple-Mail-5--1021928446
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


AD asks:
(12) section 7: I don't see how to send a reference to a certificate -
5.3.4 doesn't seem to allow for that now - wouldn't you need a new
CertificateType for that?

By a reference you mean, e.g., a URL?

Yeah a URL could be an example. The text says you can send a
reference to the cert but I don't see a field where I can put
e.g. a URL "thus avoiding the need to send a certificate" as
it says.

Ekr noted: This appears to be a real defect. I think it's a version
skew problem. The certificate indicators are hashes, so how does this
work?

EKR responded 6/8/12 =
https://www.ietf.org/mail-archive/web/p2psip/current/msg06225.html

In principle the SecurityBlock structure is designed to work with
certificates which are stored in the overlay and then retrieved
at verification time. In practice, however, the certificates are
indexed into the security block by Hash(cert) but stored in
the overlay under subject, so you can't retrieve them from
the overlay.

There seem to be two fixes for this:
(1) Modify(add to?) the certificate store usage to store certs
under the fingerprint so they can be retrieved.
(2) Stop claiming that you can fetch the certs and just say that
for this version you must send the certs with the message.

Is anyone interested in not sending all the certs with the message?
If so, we should do (1). Otherwise, we should do (2).

Okay folks? Which do we do?=

--Apple-Mail-5--1021928446
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; =
"><div><br></div><div>AD asks:</div><div><p style=3D"margin-top: 15px; =
margin-right: 0px; margin-bottom: 15px; margin-left: 0px; padding-top: =
0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; =
border-top-width: 0px; border-right-width: 0px; border-bottom-width: =
0px; border-left-width: 0px; border-style: initial; border-color: =
initial; color: rgb(51, 51, 51); font-family: Helvetica, arial, =
freesans, clean, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 20px; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251); position: static; z-index: auto; =
">(12) section 7: I don't see how to send a reference to a certificate =
-<br>5.3.4 doesn't seem to allow for that now - wouldn't you need a =
new<br>CertificateType for that?</p><p style=3D"margin: 15px 0px; =
padding: 0px; border: 0px; color: rgb(51, 51, 51); font-family: =
Helvetica, arial, freesans, clean, sans-serif; font-size: 13px; =
font-style: normal; font-variant: normal; font-weight: normal; =
letter-spacing: normal; line-height: 20px; orphans: 2; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(251, 251, =
251);">By a reference you mean, e.g., a URL?</p><p style=3D"margin-top: =
15px; margin-right: 0px; margin-bottom: 15px; margin-left: 0px; =
padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: =
0px; border-top-width: 0px; border-right-width: 0px; =
border-bottom-width: 0px; border-left-width: 0px; border-style: initial; =
border-color: initial; color: rgb(51, 51, 51); font-family: Helvetica, =
arial, freesans, clean, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 20px; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251); position: static; z-index: auto; =
">Yeah a URL could be an example. The text says you can send =
a<br>reference to the cert but I don't see a field where I can =
put<br>e.g. a URL "thus avoiding the need to send a certificate" =
as<br>it says.</p><p style=3D"margin-top: 15px; margin-right: 0px; =
margin-bottom: 15px; margin-left: 0px; padding-top: 0px; padding-right: =
0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; =
border-right-width: 0px; border-bottom-width: 0px; border-left-width: =
0px; border-style: initial; border-color: initial; color: rgb(51, 51, =
51); font-family: Helvetica, arial, freesans, clean, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 20px; orphans: 2; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(251, 251, 251); =
position: static; z-index: auto; ">Ekr noted: This appears to be a real =
defect. I think it's a version<br>skew problem. The certificate =
indicators are hashes, so how does this<br>work?</p><p =
style=3D"margin-top: 15px; margin-right: 0px; margin-bottom: 15px; =
margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: =
0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; =
border-bottom-width: 0px; border-left-width: 0px; border-style: initial; =
border-color: initial; color: rgb(51, 51, 51); font-family: Helvetica, =
arial, freesans, clean, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 20px; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251); position: static; z-index: auto; =
">EKR responded 6/8/12&nbsp;<a =
href=3D"https://www.ietf.org/mail-archive/web/p2psip/current/msg06225.html=
" style=3D"margin: 0px; padding: 0px; border: 0px; color: rgb(65, 131, =
196); text-decoration: =
initial;">https://www.ietf.org/mail-archive/web/p2psip/current/msg06225.ht=
ml</a></p><p style=3D"margin: 15px 0px; padding: 0px; border: 0px; =
color: rgb(51, 51, 51); font-family: Helvetica, arial, freesans, clean, =
sans-serif; font-size: 13px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: 20px; orphans: =
2; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251);">In principle the SecurityBlock =
structure is designed to work with<br>certificates which are stored in =
the overlay and then retrieved<br>at verification time. In practice, =
however, the certificates are<br>indexed into the security block by =
Hash(cert) but stored in<br>the overlay under subject, so you can't =
retrieve them from<br>the overlay.</p><p style=3D"margin: 15px 0px; =
padding: 0px; border: 0px; color: rgb(51, 51, 51); font-family: =
Helvetica, arial, freesans, clean, sans-serif; font-size: 13px; =
font-style: normal; font-variant: normal; font-weight: normal; =
letter-spacing: normal; line-height: 20px; orphans: 2; text-align: =
start; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(251, 251, =
251);">There seem to be two fixes for this:<br>(1) Modify(add to?) the =
certificate store usage to store certs<br>under the fingerprint so they =
can be retrieved.<br>(2) Stop claiming that you can fetch the certs and =
just say that<br>for this version you must send the certs with the =
message.</p><p style=3D"margin-top: 15px; margin-right: 0px; =
margin-bottom: 0px !important; margin-left: 0px; padding-top: 0px; =
padding-right: 0px; padding-bottom: 0px; padding-left: 0px; =
border-top-width: 0px; border-right-width: 0px; border-bottom-width: =
0px; border-left-width: 0px; border-style: initial; border-color: =
initial; color: rgb(51, 51, 51); font-family: Helvetica, arial, =
freesans, clean, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 20px; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251); position: static; z-index: auto; =
">Is anyone interested in not sending all the certs with the =
message?<br>If so, we should do (1). Otherwise, we should do (2).</p><p =
style=3D"margin-top: 15px; margin-right: 0px; margin-bottom: 0px =
!important; margin-left: 0px; padding-top: 0px; padding-right: 0px; =
padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; =
border-right-width: 0px; border-bottom-width: 0px; border-left-width: =
0px; border-style: initial; border-color: initial; color: rgb(51, 51, =
51); font-family: Helvetica, arial, freesans, clean, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 20px; orphans: 2; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(251, 251, 251); =
position: static; z-index: auto; "><br></p><p style=3D"margin-top: 15px; =
margin-right: 0px; margin-bottom: 0px !important; margin-left: 0px; =
padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: =
0px; border-top-width: 0px; border-right-width: 0px; =
border-bottom-width: 0px; border-left-width: 0px; border-style: initial; =
border-color: initial; color: rgb(51, 51, 51); font-family: Helvetica, =
arial, freesans, clean, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 20px; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(251, 251, 251); position: static; z-index: auto; =
">Okay folks? Which do we do?</p></div></body></html>=

--Apple-Mail-5--1021928446--

From dean.willis@softarmor.com  Fri Nov 16 12:16:57 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C6C121F85DF for <p2psip@ietfa.amsl.com>; Fri, 16 Nov 2012 12:16:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.556
X-Spam-Level: 
X-Spam-Status: No, score=-103.556 tagged_above=-999 required=5 tests=[AWL=0.042, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z8kE8lRNzfNc for <p2psip@ietfa.amsl.com>; Fri, 16 Nov 2012 12:16:56 -0800 (PST)
Received: from mail-ob0-f172.google.com (mail-ob0-f172.google.com [209.85.214.172]) by ietfa.amsl.com (Postfix) with ESMTP id 59CBB21F8485 for <p2psip@ietf.org>; Fri, 16 Nov 2012 12:16:56 -0800 (PST)
Received: by mail-ob0-f172.google.com with SMTP id ef5so3391617obb.31 for <p2psip@ietf.org>; Fri, 16 Nov 2012 12:16:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=subject:from:content-type:message-id:date:cc:to:mime-version :x-mailer; bh=GrqgX1YkOtcNBLaCQWegHuEXQI8NCUmCh6V9Wa96NXI=; b=V6OR2xZf3b6SkK0+Tt4pl4MV9cLyKWbJd1dFS58gsmKf1E+4w/G6mJ4URFsrTgo+lp bKjYwNFp39vZ8Ue5sP+3nmPCE+N/AOpV6zzQbbqnCappgu+fRFXpQ6S5Uxm83MalRpIU b68NLtc6Uk1x19e9PnlHwGgmpnEfe0YXhnXb0=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:from:content-type:message-id:date:cc:to:mime-version :x-mailer:x-gm-message-state; bh=GrqgX1YkOtcNBLaCQWegHuEXQI8NCUmCh6V9Wa96NXI=; b=lXq64YrDKJ3OLRp+LmyxjpXpZL30qA1zQ5mHN56srzKpIH15aukXlN5yqgCXGT7q6R RBf4/17TIjik1l7eReX1tKc6piN9/VK9UjOLpNMnBniXVF0YHEqVy/mfBxBHkBT6LfW6 8uf6MCmLwBi6+MQmrSXq+dVuIswzQDNNHN3ids3/DZEHqogwnBvRfutnAcZkAG41ABfA bjwM9bEKeEOjSyKzbS/Wo9mMaq0S6GOA8Zt/W6GI2Tr4Ry5vfLCy72UYluQZUqS+iI3k pRJcoc57nQ42tRqxpcPN1wdNecSOUOWb/qi9ozmtKevn9R0dMNpJX7jUHtZlWOBuNPPV 40wQ==
Received: by 10.182.127.102 with SMTP id nf6mr5018298obb.14.1353097015434; Fri, 16 Nov 2012 12:16:55 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id o3sm2418188obk.13.2012.11.16.12.16.54 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 16 Nov 2012 12:16:54 -0800 (PST)
From: Dean Willis <dean.willis@softarmor.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-6--1019824639
Message-Id: <F3864E4B-B0A5-4837-86D7-A68478B3ADAA@softarmor.com>
Date: Fri, 16 Nov 2012 14:16:53 -0600
To: Eric Rescorla <ekr@rtfm.com>, Cullen Jennings <fluffy@cisco.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQmepfp2naBtK17EFrPopgM3DgYAUHAOlFbsyL1zDuymboLefPFWR+JsRrFwFvHvYZCqMASh
Cc: p2psip@ietf.org
Subject: [P2PSIP] RELOAD BAse: Grammar for overlay name?
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Nov 2012 20:16:57 -0000

--Apple-Mail-6--1019824639
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

Stephen Farrell asks: in 14.15: is reg-name sufficiently clear for the =
overlay name? For example, that allows percent encoding - are those =
variant names all the same overlay? I guess so, but it'd be good to =
confirm and maybe say that in the document.

Marc and I looked at it during IETF 85 and thought maybe reg-name was =
not a good fit. What should be used here?

--
Dean


--Apple-Mail-6--1019824639
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span =
style=3D"color: rgb(0, 0, 0); font-family: arial, sans, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: left; text-indent: 0px; text-transform: none; white-space: =
pre-wrap; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;">Stephen Farrell asks: in =
14.15: is reg-name sufficiently clear for the overlay name? For example, =
that allows percent encoding - are those variant names all the same =
overlay? I guess so, but it'd be good to confirm </span><span =
style=3D"color: rgb(0, 0, 0); font-family: arial, sans, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: left; text-indent: 0px; text-transform: none; white-space: =
pre-wrap; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;">and maybe say that in the =
document.</span><div><span style=3D"color: rgb(0, 0, 0); font-family: =
arial, sans, sans-serif; font-size: 13px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: 2; text-align: left; text-indent: 0px; =
text-transform: none; white-space: pre-wrap; widows: 2; word-spacing: =
0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
background-color: rgb(255, 255, 255); display: inline !important; float: =
none;"><br></span></div><div><span style=3D"color: rgb(0, 0, 0); =
font-family: arial, sans, sans-serif; font-size: 13px; font-style: =
normal; font-variant: normal; font-weight: normal; letter-spacing: =
normal; line-height: normal; orphans: 2; text-align: left; text-indent: =
0px; text-transform: none; white-space: pre-wrap; widows: 2; =
word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;">Marc and I looked at it during =
IETF 85 and thought maybe reg-name was not a good fit. What should be =
used here?</span></div><div><span style=3D"color: rgb(0, 0, 0); =
font-family: arial, sans, sans-serif; font-size: 13px; font-style: =
normal; font-variant: normal; font-weight: normal; letter-spacing: =
normal; line-height: normal; orphans: 2; text-align: left; text-indent: =
0px; text-transform: none; white-space: pre-wrap; widows: 2; =
word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;"><br></span></div><div><span =
style=3D"color: rgb(0, 0, 0); font-family: arial, sans, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: left; text-indent: 0px; text-transform: none; white-space: =
pre-wrap; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;">--</span></div><div><span =
style=3D"color: rgb(0, 0, 0); font-family: arial, sans, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: left; text-indent: 0px; text-transform: none; white-space: =
pre-wrap; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: none;">Dean</span></div><div><span =
style=3D"color: rgb(0, 0, 0); font-family: arial, sans, sans-serif; =
font-size: 13px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: normal; orphans: 2; =
text-align: left; text-indent: 0px; text-transform: none; white-space: =
pre-wrap; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); =
display: inline !important; float: =
none;"><br></span></div></body></html>=

--Apple-Mail-6--1019824639--

From dean.willis@softarmor.com  Wed Nov 21 10:50:10 2012
Return-Path: <dean.willis@softarmor.com>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6676121F87AC for <p2psip@ietfa.amsl.com>; Wed, 21 Nov 2012 10:50:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.561
X-Spam-Level: 
X-Spam-Status: No, score=-103.561 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YtPM3-GgERQQ for <p2psip@ietfa.amsl.com>; Wed, 21 Nov 2012 10:50:09 -0800 (PST)
Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) by ietfa.amsl.com (Postfix) with ESMTP id 7B8F321F8609 for <p2psip@ietf.org>; Wed, 21 Nov 2012 10:50:09 -0800 (PST)
Received: by mail-oa0-f44.google.com with SMTP id n5so8024911oag.31 for <p2psip@ietf.org>; Wed, 21 Nov 2012 10:50:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=softarmor.com; s=google; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:from:subject:date:to:x-mailer; bh=brtKbEnJZaoy+tf3s59+PT4Y9oM1RNaSqx3ABvdQh20=; b=AmKjjtQ5SATpsgHSaw7ZdumPLQoTxaouOwGrQaHsnx0Yazjn0MM19dWKtkhmomnOZY ofGTiZAuP+ZEHGV8fobkHx+TvLVQSKECL6GMLZs65gGPAXKNDvLhOEWeRDYbtR5M2cst bJaXIS9PHcHJAXq6gE1d0CJAMfB6Klu8pGzRs=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=references:in-reply-to:mime-version:content-type:message-id :content-transfer-encoding:from:subject:date:to:x-mailer :x-gm-message-state; bh=brtKbEnJZaoy+tf3s59+PT4Y9oM1RNaSqx3ABvdQh20=; b=Zjkbm7L1LrQqgiPY4t4d7idpe1e/Msp76j18ATQj5Kvu3sonmodyMKf8SiRkqo4JTO IKtdbA0xAQFDBJpoWPDwQWr/fWjT2eOBx7vBDKEk2yR3athhjcC0Vh1PNgzsBgEPCqV/ bd78Kj6a0GLHy0GXZTdtWMzh3uimspMgE1YvewwMmLAvoez43ItxBCRYHIsiA/WiDhkn Nwle4JqaGnYJm2JpWNR14g9bRDw0UZWxyAGyhzkrLoCHRkTVSSNWz8M3Sw11PKZ4NVT4 bC7FR2Af1R3VMCHVmjX7Of1BlniQToBuMdD32aywHM5XRhPBNEKsY4bpINHLWkDFu7xA qRwA==
Received: by 10.182.2.169 with SMTP id 9mr9864099obv.66.1353523808930; Wed, 21 Nov 2012 10:50:08 -0800 (PST)
Received: from [192.168.2.119] (cpe-72-181-157-19.tx.res.rr.com. [72.181.157.19]) by mx.google.com with ESMTPS id j7sm791085obv.7.2012.11.21.10.50.07 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 21 Nov 2012 10:50:08 -0800 (PST)
References: <5CA52C99-86B9-4FE8-9AC4-077F3C48DCE6@softarmor.com> <0D27E951-A0AF-4DFD-BE16-5C7F36BEADA5@softarmor.com>
In-Reply-To: <0D27E951-A0AF-4DFD-BE16-5C7F36BEADA5@softarmor.com>
Mime-Version: 1.0 (Apple Message framework v1085)
Content-Type: text/plain; charset=us-ascii
Message-Id: <6F029BB4-CDD8-42A1-BDB7-E7BA4CF414D3@softarmor.com>
Content-Transfer-Encoding: quoted-printable
From: Dean Willis <dean.willis@softarmor.com>
Date: Wed, 21 Nov 2012 12:50:06 -0600
To: p2psip@ietf.org
X-Mailer: Apple Mail (2.1085)
X-Gm-Message-State: ALoCoQklT+79E9TrlznlTZxz9XmwWLn5Cf5smnwndhYCY+3WNTovKqyZyxWreitnIPF2ZcmSQ6Ph
Subject: Re: [P2PSIP] RELOAD Base cert expiry
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Nov 2012 18:50:10 -0000

On Nov 14, 2012, at 4:48 PM, Dean Willis wrote:

>=20
> On Nov 9, 2012, at 10:46 AM, Dean Willis wrote:
>=20
>> AD asks:
>>=20
>> section 7.4.2.2: If the signer's cert has expired, is a signature on =
a stored value still considered valid or not? One issue is that if any =
revocation/status checking is supported then there may not be any such =
information available for expired certs. Another issue is that if you do =
consider signatures only verifiable with non-expired certs, then a lot =
can go wrong when a cert expires and its hard to fix that up. I don't =
have a good solution to offer, but maybe you have an answer?
>>=20
>> In the current doc, 7.1 says:
>>  When signatures are verified, the current time MUST
>>  be compared to the certificate validity period.  However, it is
>>  permitted to have a value signed which expires after a certificate's
>>  validity period (though this will likely cause verification failure
>>  at some future time.)
>>=20
>> I understand that some implementations flush any object for which the =
signing certificate has expired; that is, the upper TTL for an object is =
the remaining validity period for the signing certificate. This could be =
enforced on insertion, or by audit/cleanup processes.
>>=20
>> How do we want to handle it?
>>=20
>>=20
>=20
> I met today with Cullen and EKR on this one.
>=20
> We agree that we need to clarify in 7.4.2.2 that a signature from an =
expired cert is not valid, and that implementations may garbage-collect =
data signed by expired certs at their discretion. We can add a =
back-reference to the validity testing section in 7.1

Here's my submitted text:

        <t>Note that there is no relationship between the validity
        window of a certificate and the expiry of the data it is
        authenticating. When signatures are verified, the current time
        MUST be compared to the certificate validity period. Stored
        data MAY be set to expire after the signing certificate's
        validity period. Such signatures are not considered valid
        after the signing certificate expires. Implementations may
        garbage collect such data at their convenience, either purging
        it automatically (perhaps by setting the upper bound on data
        storage to the lifetime of the signing certificate) or by
        simply leaving it in-place until it expires naturally and
        relying on users of that data to notice the expired signing
        certificate.</t>

--
Dean




From petithug@acm.org  Sat Nov 24 09:52:56 2012
Return-Path: <petithug@acm.org>
X-Original-To: p2psip@ietfa.amsl.com
Delivered-To: p2psip@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 85E6B21F8555 for <p2psip@ietfa.amsl.com>; Sat, 24 Nov 2012 09:52:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.811
X-Spam-Level: 
X-Spam-Status: No, score=-101.811 tagged_above=-999 required=5 tests=[AWL=-0.700, BAYES_05=-1.11, NO_RELAYS=-0.001, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uv9c-PHe1Arm for <p2psip@ietfa.amsl.com>; Sat, 24 Nov 2012 09:52:55 -0800 (PST)
Received: from implementers.org (implementers.org [IPv6:2604:3400:dc1:41:216:3eff:fe5b:8240]) by ietfa.amsl.com (Postfix) with ESMTP id B38D021F8553 for <p2psip@ietf.org>; Sat, 24 Nov 2012 09:52:55 -0800 (PST)
Received: from [IPv6:2601:9:4b80:32:24fc:7714:d3e0:81ba] (unknown [IPv6:2601:9:4b80:32:24fc:7714:d3e0:81ba]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (Client CN "Marc Petit-Huguenin", Issuer "implementers.org" (verified OK)) by implementers.org (Postfix) with ESMTPS id 9754120194; Sat, 24 Nov 2012 17:52:53 +0000 (UTC)
Message-ID: <50B10977.1080605@acm.org>
Date: Sat, 24 Nov 2012 09:52:55 -0800
From: Marc Petit-Huguenin <petithug@acm.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:10.0.11) Gecko/20121122 Icedove/10.0.11
MIME-Version: 1.0
To: P2PSIP Mailing List <p2psip@ietf.org>, reload@implementers.org
X-Enigmail-Version: 1.4.1
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Subject: [P2PSIP] 2nd RELOAD interoperability testing event
X-BeenThere: p2psip@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Peer-to-Peer SIP working group discussion list <p2psip.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/p2psip>, <mailto:p2psip-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/p2psip>
List-Post: <mailto:p2psip@ietf.org>
List-Help: <mailto:p2psip-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/p2psip>, <mailto:p2psip-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Nov 2012 17:52:56 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

There is probably just enough time to start working on a new RELOAD
implementation so this is the second reminder for the RELOAD interoperability
event in Berlin, Germany on July 27 and 28 2013 (the Saturday and Sunday just
before IETF 87). We have an agreement on principle for where the interop event
will take place, and I am happy to announce that this time we will have
Internet access for the two days.  The full details will be sent here after
IETF 86 in Orlando, FL.

Face to face events are great for new implementations or to test complex
scenarios, but remote testing is also useful for more mature implementations.
So I would like to also remind of the availability of a service that provides
virtual RELOAD configuration and enrollment servers.  This is a free service
for RELOAD implementers that want to test their implementation remotely
against other implementations.  More details are available here:

http://blog.marc.petit-huguenin.org/2012/08/a-configuration-and-enrollment-service.html

- -- 
Marc Petit-Huguenin
Email: marc@petit-huguenin.org
Blog: http://blog.marc.petit-huguenin.org
Profile: http://www.linkedin.com/in/petithug

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJQsQl0AAoJECnERZXWan7EZ7kP/A30vKzBrL0w6yxEBJQHYyUV
5FlwFy8TavD5U0B7A4RQPFdHUt6z7DGVQVQ1j2Gi7Zreh3DYXH62ZXcxGv6kxefy
HO6CGTJgIbcQycOWFKiD0Rr4cVjqU/tD1VKFgmcfiiZIaTGIAMWhFGYgMmQfrIZc
Nh165P1eGRt/JuNO1UB59WoxpXwiGk6Sp27TvzgLVmGhm+gZr7qy8tZE7kyf6NNn
ZUjn7nw8l/wbt6XVuEsAuts7xieDzJWxHf2yG8z630nSig5f63cVmB/lJc9N0i62
M/0Kuuf9rY9hj2IIyU/3vLsBJKOHmit1znjqpccUGs2qXkID1mBJCk0D8aA6O7Sc
WoofKwcpNKaf0P9QYbtUSiSyDvqyhMQJmSqBYd9B8nr3viYX1JmssBFV0G8NOw5G
dOII7n8vKQqHc35M9hyK6oi6wUETwwu5hevc/qUtLatnbSGxGUWMChNmrMcnUjk8
6b9U4tbOC+k2Q/WAtOBFgEpHxRvcC8J6jNjx9NocHUVQq8t5o8FJiW1/YRww4ryy
pz7yIMs2bllpi4YsZWg8r1cOr90+M0DGT+9PgPeqeRCQG5cCQvwK7DRQBvPwsYHu
MbVvoGWUGJPX8RtmFewImacAn4zBsiYVEnS41yuBz/+O7SVpj8Hr+PieaJA38WQq
qKBGXNT2MsXGGbVlDY39
=jOIU
-----END PGP SIGNATURE-----
