
From mary.barnes@nortel.com  Thu Jun 11 06:45:12 2009
Return-Path: <mary.barnes@nortel.com>
X-Original-To: sip-ops@core3.amsl.com
Delivered-To: sip-ops@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4ABBA3A6AFA; Thu, 11 Jun 2009 06:45:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.585
X-Spam-Level: 
X-Spam-Status: No, score=-6.585 tagged_above=-999 required=5 tests=[AWL=0.014,  BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jxKHEKobPHui; Thu, 11 Jun 2009 06:45:11 -0700 (PDT)
Received: from zcars04e.nortel.com (zcars04e.nortel.com [47.129.242.56]) by core3.amsl.com (Postfix) with ESMTP id 2A0493A693C; Thu, 11 Jun 2009 06:45:11 -0700 (PDT)
Received: from zrc2hxm0.corp.nortel.com (zrc2hxm0.corp.nortel.com [47.103.123.71]) by zcars04e.nortel.com (Switch-2.2.0/Switch-2.2.0) with ESMTP id n5BDhs307375; Thu, 11 Jun 2009 13:43:55 GMT
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Thu, 11 Jun 2009 08:47:43 -0500
Message-ID: <1ECE0EB50388174790F9694F77522CCF1E727FEF@zrc2hxm0.corp.nortel.com>
In-Reply-To: <1241379400.3528.50.camel@scott>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: [dispatch] draft-lawrence-sip-3rd-party-authorization-00
Thread-Index: AcnMJo0K7J8DEyoPR4Wk1evGXxhUVAedGCrQ
References: <1241379400.3528.50.camel@scott>
From: "Mary Barnes" <mary.barnes@nortel.com>
To: "RAI DISPATCH" <dispatch@ietf.org>
Cc: SIP Operations <sip-ops@ietf.org>
Subject: Re: [sip-ops] [dispatch] draft-lawrence-sip-3rd-party-authorization-00
X-BeenThere: sip-ops@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: SIP Operations <sip-ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sip-ops>
List-Post: <mailto:sip-ops@ietf.org>
List-Help: <mailto:sip-ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Jun 2009 13:45:12 -0000

Hi folks,

There seems to be sufficient interest in this topic to warrant f2f
agenda time in Stockholm. However, additional feedback prior to IETF-75
is necessary to ensure that progress can be made in Stockholm.=20

Thanks,
Mary.=20
DISPATCH WG co-chair

-----Original Message-----
From: dispatch-bounces@ietf.org [mailto:dispatch-bounces@ietf.org] On
Behalf Of Lawrence, Scott (BL60:9D30)
Sent: Sunday, May 03, 2009 2:37 PM
To: RAI DISPATCH
Cc: SIP Operations
Subject: [dispatch] draft-lawrence-sip-3rd-party-authorization-00

draft-lawrence-sip-3rd-party-authorization-00.txt has been submitted by
Scott Lawrence and posted to the IETF repository.

Filename:	 draft-lawrence-sip-3rd-party-authorization
Revision:	 00
Title:		 Third Party Authorization in the Session Initiation
Protocol
Creation_date:	 2009-05-03
WG ID:		 Independent Submission
Number_of_pages: 15

Abstract:
        This draft describes some circumstances that are common in SIP
        deployments which lack a rigorous authorization model, and
points out
        some ways in which this has resulted in poor security
        characteristics.
       =20
        The purpose of this document is to stimulate discussion of the
        identified problem and proposed requirements for any solution.

In this draft, I lay out a case for why SIP would benefit from an
authorization model that allows for one party to send a request to a
second party who must decide whether or not to allow the request, but
have a third party provide an explicit authorization in the request.
The goal is to allow separation of the evaluation of a request with
respect to a security policy from other parts of responding to the
request.

I _do_not_ include any discussion in this draft of _how_ the
requirements it lists could or should be met.  While I'm very interested
in that discussion, I think it's important to first discover whether or
not there is agreement in the SIP community that there really is a
problem and what part or parts of that problem need to be solved; this
draft is focused on that discussion.



_______________________________________________
dispatch mailing list
dispatch@ietf.org
https://www.ietf.org/mailman/listinfo/dispatch

From dworley@nortel.com  Fri Jun 12 12:36:29 2009
Return-Path: <dworley@nortel.com>
X-Original-To: sip-ops@core3.amsl.com
Delivered-To: sip-ops@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 958353A6858; Fri, 12 Jun 2009 12:36:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.67
X-Spam-Level: 
X-Spam-Status: No, score=-6.67 tagged_above=-999 required=5 tests=[AWL=-0.071,  BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b1Xd3jw7it8z; Fri, 12 Jun 2009 12:36:29 -0700 (PDT)
Received: from zcars04e.nortel.com (zcars04e.nortel.com [47.129.242.56]) by core3.amsl.com (Postfix) with ESMTP id A0ED23A68CB; Fri, 12 Jun 2009 12:36:28 -0700 (PDT)
Received: from zrtphxs1.corp.nortel.com (casmtp.ca.nortel.com [47.140.202.46]) by zcars04e.nortel.com (Switch-2.2.0/Switch-2.2.0) with ESMTP id n5CJZC110248; Fri, 12 Jun 2009 19:35:12 GMT
Received: from [47.16.90.165] ([47.16.90.165]) by zrtphxs1.corp.nortel.com with Microsoft SMTPSVC(6.0.3790.3959);  Fri, 12 Jun 2009 15:36:31 -0400
From: "Dale Worley" <dworley@nortel.com>
To: "Mary Barnes" <mary.barnes@nortel.com>
In-Reply-To: <1ECE0EB50388174790F9694F77522CCF1E727FEF@zrc2hxm0.corp.nortel.com>
References: <1241379400.3528.50.camel@scott> <1ECE0EB50388174790F9694F77522CCF1E727FEF@zrc2hxm0.corp.nortel.com>
Content-Type: text/plain
Organization: Nortel Networks
Date: Fri, 12 Jun 2009 15:36:30 -0400
Message-Id: <1244835390.3768.62.camel@victoria-pingtel-com.us.nortel.com>
Mime-Version: 1.0
X-Mailer: Evolution 2.12.3 (2.12.3-5.fc8) 
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 12 Jun 2009 19:36:31.0492 (UTC) FILETIME=[16619C40:01C9EB95]
Cc: SIP Operations <sip-ops@ietf.org>, RAI DISPATCH <dispatch@ietf.org>
Subject: Re: [sip-ops] [dispatch] draft-lawrence-sip-3rd-party-authorization-00
X-BeenThere: sip-ops@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: SIP Operations <sip-ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sip-ops>
List-Post: <mailto:sip-ops@ietf.org>
List-Help: <mailto:sip-ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Jun 2009 19:36:29 -0000

On Thu, 2009-06-11 at 08:47 -0500, Mary Barnes wrote:
> There seems to be sufficient interest in this topic to warrant f2f
> agenda time in Stockholm. However, additional feedback prior to IETF-75
> is necessary to ensure that progress can be made in Stockholm. 

It looks like a good description of the problem.  Since the I-D is not
to discuss solutions, I'm not sure what there is to discuss until we
open the discussion to solutions.

Dale



From mary.barnes@nortel.com  Fri Jun 12 13:52:25 2009
Return-Path: <mary.barnes@nortel.com>
X-Original-To: sip-ops@core3.amsl.com
Delivered-To: sip-ops@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 367653A6897; Fri, 12 Jun 2009 13:52:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.467
X-Spam-Level: 
X-Spam-Status: No, score=-6.467 tagged_above=-999 required=5 tests=[AWL=0.132,  BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WHwGXKm7o94h; Fri, 12 Jun 2009 13:52:24 -0700 (PDT)
Received: from zcars04e.nortel.com (zcars04e.nortel.com [47.129.242.56]) by core3.amsl.com (Postfix) with ESMTP id 0CBDA3A6862; Fri, 12 Jun 2009 13:52:23 -0700 (PDT)
Received: from zrc2hxm0.corp.nortel.com (zrc2hxm0.corp.nortel.com [47.103.123.71]) by zcars04e.nortel.com (Switch-2.2.0/Switch-2.2.0) with ESMTP id n5CKp9121134; Fri, 12 Jun 2009 20:51:09 GMT
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Fri, 12 Jun 2009 15:54:30 -0500
Message-ID: <1ECE0EB50388174790F9694F77522CCF1E7D859B@zrc2hxm0.corp.nortel.com>
In-Reply-To: <1244835390.3768.62.camel@victoria-pingtel-com.us.nortel.com>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: [dispatch] draft-lawrence-sip-3rd-party-authorization-00
Thread-Index: AcnrlRbDZvGjDVZ5TPir0s0fgoUX3gACCmqg
References: <1241379400.3528.50.camel@scott> <1ECE0EB50388174790F9694F77522CCF1E727FEF@zrc2hxm0.corp.nortel.com> <1244835390.3768.62.camel@victoria-pingtel-com.us.nortel.com>
From: "Mary Barnes" <mary.barnes@nortel.com>
To: "Dale Worley" <dworley@nortel.com>
Cc: SIP Operations <sip-ops@ietf.org>, RAI DISPATCH <dispatch@ietf.org>
Subject: Re: [sip-ops] [dispatch] draft-lawrence-sip-3rd-party-authorization-00
X-BeenThere: sip-ops@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: SIP Operations <sip-ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sip-ops>
List-Post: <mailto:sip-ops@ietf.org>
List-Help: <mailto:sip-ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sip-ops>, <mailto:sip-ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Jun 2009 20:52:25 -0000

Correct - we are not discussing solutions because we don't develop
solutions in DISPATCH. =20
The idea in DISPATCH if folks agree that there is a problem, is to then
determine the scope of the problem to be solved - that's not been
entirely concluded for this topic. If that can happen on the ML prior to
Stockholm, then certainly no f2f time is needed - really the ideal
operation of DISPATCH is that we don't need f2f time - i.e., work comes
in, we figure out the scope of the problem, whether there is critical
mass in the WG in terms of contributing to the work and then figure out
whether we need a new WG, a BoF, an individual/AD doc, etc. =20

At this point, for this topic, there has not yet been a critical mass in
terms of feedback on the proposal - that's what we're asking for now.
Basically, we are still dealing with the "...what part or parts of that
problem need to be solved" aspect of this topic.  If we don't get more
input it is highly unlikely that any progress could be made on this
topic in Stockholm, which would put us at the point that you are
suggesting we are now in terms of having nothing to discuss. That was
the implication of my "However...".  I'll be more blunt next time.=20

Thanks,
Mary.=20

-----Original Message-----
From: Worley, Dale (BL60:9D30)=20
Sent: Friday, June 12, 2009 2:37 PM
To: Barnes, Mary (RICH2:AR00)
Cc: RAI DISPATCH; SIP Operations
Subject: Re: [dispatch] draft-lawrence-sip-3rd-party-authorization-00

On Thu, 2009-06-11 at 08:47 -0500, Mary Barnes wrote:
> There seems to be sufficient interest in this topic to warrant f2f=20
> agenda time in Stockholm. However, additional feedback prior to=20
> IETF-75 is necessary to ensure that progress can be made in Stockholm.

It looks like a good description of the problem.  Since the I-D is not
to discuss solutions, I'm not sure what there is to discuss until we
open the discussion to solutions.

Dale


