
From gonzalo.camarillo@ericsson.com  Tue Jan 11 07:35:42 2011
Return-Path: <gonzalo.camarillo@ericsson.com>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 646163A67A8 for <speermint@core3.amsl.com>; Tue, 11 Jan 2011 07:35:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.607
X-Spam-Level: 
X-Spam-Status: No, score=-106.607 tagged_above=-999 required=5 tests=[AWL=-0.008, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QCl-hAt9+svB for <speermint@core3.amsl.com>; Tue, 11 Jan 2011 07:35:41 -0800 (PST)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by core3.amsl.com (Postfix) with ESMTP id 451A93A6809 for <speermint@ietf.org>; Tue, 11 Jan 2011 07:35:41 -0800 (PST)
X-AuditID: c1b4fb3d-b7b89ae0000036a3-6a-4d2c79552b6d
Received: from esessmw0184.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id 89.B6.13987.5597C2D4; Tue, 11 Jan 2011 16:37:57 +0100 (CET)
Received: from [131.160.126.193] (153.88.115.8) by esessmw0184.eemea.ericsson.se (153.88.115.82) with Microsoft SMTP Server id 8.2.234.1; Tue, 11 Jan 2011 16:37:56 +0100
Message-ID: <4D2C7953.2080903@ericsson.com>
Date: Tue, 11 Jan 2011 17:37:55 +0200
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: "Livingood, Jason" <Jason_Livingood@cable.comcast.com>
References: <C9300A7F.1109C%jason_livingood@cable.comcast.com>
In-Reply-To: <C9300A7F.1109C%jason_livingood@cable.comcast.com>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
Cc: "speermint@ietf.org" <speermint@ietf.org>
Subject: Re: [Speermint] AD review: draft-ietf-speermint-architecture-16.txt
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Jan 2011 15:35:42 -0000

Hi Jason,

thanks. I have just requested an IETF LC for this draft. I will start
shortly.

Cheers,

Gonzalo

On 20/12/2010 11:55 PM, Livingood, Jason wrote:
> The new updated draft (-17) has now been published (notification should
> hit the list shortly).
> 
> BTW, I also updated section 3 to note that parties are equally likely to
> perform the BYE.
> 
> Regards
> Jason
> 
> 
> 
> On 12/16/10 4:05 AM, "Gonzalo Camarillo" <Gonzalo.Camarillo@ericsson.com>
> wrote:
> 
>> Hi Jason,
>>
>> thanks for addressing my comments. When you submit the new revision I
>> will take care of starting its IETF LC.
>>
>>>> Section 3. Why is the sending of the BYE (step 5) more likely to be
>>>> performed by the target SSP than by the originating SSP?
>>>
>>> It just seemed logical as we envisioned the call flow between two people
>>> in our head. 
>>>
>>> QUESTION: Would you like a modification there?
>>
>> well, this is a small detail, so I leave it up to you whether or not you
>> want to state that step 5 is likely to be performed by the target SSP or
>> that it can be performed by either of them.
>>
>> I have not seen any statistics about who is more likely to hang up when
>> involved in a call, the callee or the caller. However, in the PSTN, the
>> terminating switch will not send a REL even if the callee hangs up. This
>> allows the callee to hang up, move to another telephone, and pick up
>> there in order to continue the conversation (i.e., the single line
>> extension service). So, at least in the PSTN, you are much more likely
>> to see REL messages in the caller to callee direction.
>>
>> In any case, as I said before, this is a minor point. We have probably
>> already spent to much time on it :o)
>>
>> Thanks,
>>
>> Gonzalo
> 


From iesg-secretary@ietf.org  Tue Jan 11 09:26:19 2011
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3E9433A6A5F; Tue, 11 Jan 2011 09:26:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.386
X-Spam-Level: 
X-Spam-Status: No, score=-102.386 tagged_above=-999 required=5 tests=[AWL=0.213, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SvfJVRrlxTlc; Tue, 11 Jan 2011 09:26:18 -0800 (PST)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4CEA93A677E; Tue, 11 Jan 2011 09:26:18 -0800 (PST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: IETF-Announce <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 3.10
Message-ID: <20110111172618.8029.20210.idtracker@localhost>
Date: Tue, 11 Jan 2011 09:26:18 -0800
Cc: speermint@ietf.org
Subject: [Speermint] Last Call: <draft-ietf-speermint-architecture-17.txt> (Session	PEERing for Multimedia INTerconnect Architecture) to Informational RFC
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Jan 2011 17:26:19 -0000

The IESG has received a request from the Session PEERing for Multimedia
INTerconnect WG (speermint) to consider the following document:
- 'Session PEERing for Multimedia INTerconnect Architecture'
  <draft-ietf-speermint-architecture-17.txt> as an Informational RFC

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2011-01-25. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the
beginning of the Subject line to allow automated sorting.

The file can be obtained via
http://datatracker.ietf.org/doc/draft-ietf-speermint-architecture/

IESG discussion can be tracked via
http://datatracker.ietf.org/doc/draft-ietf-speermint-architecture/


No IPR declarations have been submitted directly on this I-D.

From gonzalo.camarillo@ericsson.com  Tue Jan 18 07:53:12 2011
Return-Path: <gonzalo.camarillo@ericsson.com>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 378473A7027 for <speermint@core3.amsl.com>; Tue, 18 Jan 2011 07:53:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.613
X-Spam-Level: 
X-Spam-Status: No, score=-106.613 tagged_above=-999 required=5 tests=[AWL=-0.014, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3UaWTkhc9Eoq for <speermint@core3.amsl.com>; Tue, 18 Jan 2011 07:53:09 -0800 (PST)
Received: from mailgw9.se.ericsson.net (mailgw9.se.ericsson.net [193.180.251.57]) by core3.amsl.com (Postfix) with ESMTP id 5E7413A7026 for <speermint@ietf.org>; Tue, 18 Jan 2011 07:53:09 -0800 (PST)
X-AuditID: c1b4fb39-b7cfbae000005c8e-22-4d35b80123ea
Received: from esessmw0191.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw9.se.ericsson.net (Symantec Mail Security) with SMTP id B6.EA.23694.108B53D4; Tue, 18 Jan 2011 16:55:45 +0100 (CET)
Received: from [131.160.126.246] (153.88.115.8) by esessmw0191.eemea.ericsson.se (153.88.115.85) with Microsoft SMTP Server id 8.2.234.1; Tue, 18 Jan 2011 16:55:45 +0100
Message-ID: <4D35B801.5030701@ericsson.com>
Date: Tue, 18 Jan 2011 17:55:45 +0200
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: "speermint@ietf.org" <speermint@ietf.org>
References: <4CA35805.80606@ericsson.com> <4CE26FC7.10605@ericsson.com> <4D0A2312.105@ericsson.com>
In-Reply-To: <4D0A2312.105@ericsson.com>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
Subject: Re: [Speermint] AD review: draft-ietf-speermint-voipthreats-05
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Jan 2011 15:53:12 -0000

Hi,

I still do not seem to have received any answer (see email below).

Thanks,

Gonzalo

On 16/12/2010 4:32 PM, Gonzalo Camarillo wrote:
> Hi,
> 
> I do not seem to have received an answer to my email below. If I have
> missed it, could you please resend it?
> 
> Thanks,
> 
> Gonzalo
> 
> On 16/11/2010 1:49 PM, Gonzalo Camarillo wrote:
>> Hi,
>>
>> thanks for having submitted a new revision of this draft:
>>
>> http://tools.ietf.org/html/draft-ietf-speermint-voipthreats-06
>>
>> This revision addresses most of my comments below. However, I do not
>> think I got an answer to the following question:
>>
>>> While message modification and eavesdropping is included in the
>>> threats against SF and MF, they do not seem to appear in the threats
>>> against LRF and LUF. Why?
>>
>> Also, the reasons why Section 4.5 recommends TCP over UDP are still not
>> clear. UDP over DTLS would meet the requirements in both Sections 3.2
>> and 4.5.
>>
>> Thanks,
>>
>> Gonzalo
>>
>>
>> On 29/09/2010 5:15 PM, Gonzalo Camarillo wrote:
>>> Hi,
>>>
>>> a couple of days ago I received a publication request for the following
>>> draft:
>>>
>>> https://datatracker.ietf.org/doc/draft-ietf-speermint-voipthreats/
>>>
>>> Here you have my AD review of the draft (see below). The authors should
>>> be able to address all my comments fairly quickly. As soon as they
>>> revise the draft I will initiate its IETF LC.
>>>
>>> Thanks,
>>>
>>> Gonzalo
>>>
>>>
>>> draft-ietf-speermint-voipthreats-05
>>>
>>> Expand acronyms on their first use (e.g., SPEERMINT in the title and
>>> VoIP in the Introduction).
>>>
>>> The Abstract and the Introduction attempt to explain the relationship
>>> between this draft and draft-ietf-speermint-requirements. However,
>>> Section 3.1 does a better job at that. Could you please clarify in the
>>> Introduction that the requirements in draft-ietf-speermint-requirements
>>> were derived from the threats documented in this draft? Also, please
>>> clarify that in addition to be the base for those requirements, this
>>> draft provides countermeasures to meet those requirements. Any SPEERMINT
>>> expert will probably understand that by reading the Abstract and the
>>> Introduction but clarifying those points will help readers who have not
>>> been that involved in the process.
>>>
>>> While message modification and eavesdropping is included in the
>>> threats against SF and MF, they do not seem to appear in the threats
>>> against LRF and LUF. Why?
>>>
>>> Section 4.5 recommends to use TCP instead of UDP. That advice is great,
>>> but the reasons Section 4.5 discusses are not that strong. The fact that
>>> the linux kernel has improved is irrelevant if an operator uses
>>> non-linux boxes. Also, an operator using UDP over IPsec, for instance,
>>> will not face the problems described there. The main recommendation in
>>> Section 4.5 seems to actually be to use an integrity protection
>>> mechanism. Clarifying that section would be useful.
>>>
>>> [refs.sbcfuncs] has been published as RFC 5853
>>>
>>> A few references only include the title and the author fields. Adding
>>> the venue where they were published would be useful.
>>>
>>
>> _______________________________________________
>> Speermint mailing list
>> Speermint@ietf.org
>> https://www.ietf.org/mailman/listinfo/speermint
>>
> 
> _______________________________________________
> Speermint mailing list
> Speermint@ietf.org
> https://www.ietf.org/mailman/listinfo/speermint
> 


From Internet-Drafts@ietf.org  Tue Jan 25 05:00:30 2011
Return-Path: <Internet-Drafts@ietf.org>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E42023A6BB6; Tue, 25 Jan 2011 05:00:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level: 
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4RJQhuuwuEjy; Tue, 25 Jan 2011 05:00:30 -0800 (PST)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1F3A628C102; Tue, 25 Jan 2011 05:00:02 -0800 (PST)
MIME-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
From: Internet-Drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 3.10
Message-ID: <20110125130002.13766.31869.idtracker@localhost>
Date: Tue, 25 Jan 2011 05:00:02 -0800
Cc: speermint@ietf.org
Subject: [Speermint] I-D Action:draft-ietf-speermint-voipthreats-07.txt
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Jan 2011 13:00:31 -0000

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Session PEERing for Multimedia INTerconnect Working Group of the IETF.


	Title           : Session Peering for Multimedia Interconnect (SPEERMINT) Security Threats and Suggested Countermeasures
	Author(s)       : J. Seedorf, et al.
	Filename        : draft-ietf-speermint-voipthreats-07.txt
	Pages           : 26
	Date            : 2011-01-25

The Session PEERing for Multimedia INTerconnect working group
(SPEERMINT) provides a peering framework that leverages the building
blocks of existing IETF-defined protocols such as SIP and ENUM for
the interconnection between SIP service providers.  The objective of
this document is to identify and enumerate SPEERMINT-specific threat
vectors and to give guidance for implementers on selecting
appropriate countermeasures.  Security requirements for SPEERMINT
which have been derived from the threats detailed in this document
can be found in draft-ietf-speermint-requirements; this document
provides concrete countermeasures to meet those SPEERMINT security
requirements.  In this document, the different security threats
related to SPEERMINT are classified into threats to the Lookup
Function (LUF), to the Location Routing Function (LRF), to the
Signaling Function (SF), and to the Media Function (MF).  Various
instances of the threats are briefly introduced inside the
classification.  Finally, existing security solutions for SIP and
RTP/RTCP are presented to describe countermeasures currently
available for such threats.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-speermint-voipthreats-07.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Message/External-body;
	name="draft-ietf-speermint-voipthreats-07.txt";
	site="ftp.ietf.org"; access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID: <2011-01-25045352.I-D@ietf.org>


--NextPart--

From Jan.Seedorf@neclab.eu  Tue Jan 25 05:11:46 2011
Return-Path: <Jan.Seedorf@neclab.eu>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7F4F33A6BBB for <speermint@core3.amsl.com>; Tue, 25 Jan 2011 05:11:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.377
X-Spam-Level: 
X-Spam-Status: No, score=-102.377 tagged_above=-999 required=5 tests=[AWL=0.222, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JeqodqfbGLDV for <speermint@core3.amsl.com>; Tue, 25 Jan 2011 05:11:45 -0800 (PST)
Received: from smtp0.neclab.eu (smtp0.neclab.eu [195.37.70.41]) by core3.amsl.com (Postfix) with ESMTP id E9CD43A69E2 for <speermint@ietf.org>; Tue, 25 Jan 2011 05:11:44 -0800 (PST)
Received: from localhost (localhost.localdomain [127.0.0.1]) by smtp0.neclab.eu (Postfix) with ESMTP id 455662C000341; Tue, 25 Jan 2011 14:15:19 +0100 (CET)
X-Virus-Scanned: Amavisd on Debian GNU/Linux (atlas2.office.hd)
Received: from smtp0.neclab.eu ([127.0.0.1]) by localhost (atlas2.office.hd [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sHg+KI8JYKek; Tue, 25 Jan 2011 14:15:19 +0100 (CET)
Received: from ENCELADUS.office.hd (ENCELADUS.office.hd [192.168.24.52]) by smtp0.neclab.eu (Postfix) with ESMTP id 28DA62C0001AF; Tue, 25 Jan 2011 14:14:59 +0100 (CET)
Received: from PALLENE.office.hd ([169.254.1.59]) by ENCELADUS.office.hd ([192.168.24.52]) with mapi id 14.01.0270.001; Tue, 25 Jan 2011 14:14:22 +0100
From: Jan Seedorf <Jan.Seedorf@neclab.eu>
To: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>, "speermint@ietf.org" <speermint@ietf.org>
Thread-Topic: [Speermint] AD review: draft-ietf-speermint-voipthreats-05
Thread-Index: AQHLX+kxWnxLUqNcV0qrWRp/Ps/5e5N0OA6AgG4nduA=
Date: Tue, 25 Jan 2011 13:14:20 +0000
Message-ID: <2779C9F0771F974CAD742BAE6D9904FE7EC444@PALLENE.office.hd>
References: <4CA35805.80606@ericsson.com> <4CE26FC7.10605@ericsson.com>
In-Reply-To: <4CE26FC7.10605@ericsson.com>
Accept-Language: de-DE, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.1.2.226]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: Eric Chen <eric.chen@lab.ntt.co.jp>, Saverio Niccolini <Saverio.Niccolini@neclab.eu>, "hendrik.scholz@voipfuture.com" <hendrik.scholz@voipfuture.com>
Subject: Re: [Speermint] AD review: draft-ietf-speermint-voipthreats-05
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Jan 2011 13:11:46 -0000

Dear Gonzalo,

Thanks for your - indeed valid - comments on our -06 version of draft-ietf-=
speermint-voipthreats. Sorry for taking a while, your comments resulted in =
quite some changes in the draft. I just posted a new -07 version, let me ex=
plain below how we think we addressed your comments in this version:

> > While message modification and eavesdropping is included in the
> > threats against SF and MF, they do not seem to appear in the threats
> > against LRF and LUF. Why?
Indeed message modification and eavesdropping are threats also for the LUF =
and LRF. We assumed those addressed with "confidentiality" and "integrity".=
 We added some more text now, e.g. specifically mentioning "eavesdropping" =
and "message modification" under "confidentiality" and "integrity", respect=
ively, for the LUF and LRF. For us, it was implicit that when one talks abo=
ut confidentiality he/she indirectly talks about "eavesdropping", and when =
one talks about integrity he/she indirectly talks about "message modificati=
on". Anyway, we hope the text now explicitly makes this clear.

> Also, the reasons why Section 4.5 recommends TCP over UDP are still not
> clear. UDP over DTLS would meet the requirements in both Sections 3.2
> and 4.5.
This is a very good point, which caused changes in section 4.5, 3.2, and in=
 some other parts. At the time we started writing this draft back in 2007, =
RFC4347 on DTLS was less than a year old and there was no mature implementa=
tion of DTLS at the time.  Companies designing NGN at the time did not cons=
ider DTLS for the same reason. Since it has been more than three years, now=
adays there seem to be quite a few DTLS implementations (at the IETF privac=
y workshop in Dec., I talked with Eric Rescorla about this and he confirmed=
 that some stable implementations exist by now). We now updated the section=
s, saying that transport layer security can be either DTLS or TLS, dependin=
g on the use of the underlying transport protocol (UDP or TCP). Thus, we al=
so do not recommend TCP over UDP anymore, and the section was renamed to "4=
.5 Secure Exchange of SIP messages". Accordingly, the former section "4.13.=
  Encryption and Integrity Protection of Signaling Messages" is now obsolet=
e and we had to update also section 3.2., mentioning DTLS as an alternative=
 to TLS.

We hope the draft is in better shape now and that all your comments have be=
en addressed.

Sorry again for taking so long,

 - Jan


> -----Original Message-----
> From: speermint-bounces@ietf.org [mailto:speermint-bounces@ietf.org] On B=
ehalf
> Of Gonzalo Camarillo
> Sent: Dienstag, 16. November 2010 12:49
> To: speermint@ietf.org
> Subject: Re: [Speermint] AD review: draft-ietf-speermint-voipthreats-05
>=20
> Hi,
>=20
> thanks for having submitted a new revision of this draft:
>=20
> http://tools.ietf.org/html/draft-ietf-speermint-voipthreats-06
>=20
> This revision addresses most of my comments below. However, I do not
> think I got an answer to the following question:
>=20
> > While message modification and eavesdropping is included in the
> > threats against SF and MF, they do not seem to appear in the threats
> > against LRF and LUF. Why?
>=20
> Also, the reasons why Section 4.5 recommends TCP over UDP are still not
> clear. UDP over DTLS would meet the requirements in both Sections 3.2
> and 4.5.
>=20
> Thanks,
>=20
> Gonzalo
>=20
>=20
> On 29/09/2010 5:15 PM, Gonzalo Camarillo wrote:
> > Hi,
> >
> > a couple of days ago I received a publication request for the following
> > draft:
> >
> > https://datatracker.ietf.org/doc/draft-ietf-speermint-voipthreats/
> >
> > Here you have my AD review of the draft (see below). The authors should
> > be able to address all my comments fairly quickly. As soon as they
> > revise the draft I will initiate its IETF LC.
> >
> > Thanks,
> >
> > Gonzalo
> >
> >
> > draft-ietf-speermint-voipthreats-05
> >
> > Expand acronyms on their first use (e.g., SPEERMINT in the title and
> > VoIP in the Introduction).
> >
> > The Abstract and the Introduction attempt to explain the relationship
> > between this draft and draft-ietf-speermint-requirements. However,
> > Section 3.1 does a better job at that. Could you please clarify in the
> > Introduction that the requirements in draft-ietf-speermint-requirements
> > were derived from the threats documented in this draft? Also, please
> > clarify that in addition to be the base for those requirements, this
> > draft provides countermeasures to meet those requirements. Any SPEERMIN=
T
> > expert will probably understand that by reading the Abstract and the
> > Introduction but clarifying those points will help readers who have not
> > been that involved in the process.
> >
> > While message modification and eavesdropping is included in the
> > threats against SF and MF, they do not seem to appear in the threats
> > against LRF and LUF. Why?
> >
> > Section 4.5 recommends to use TCP instead of UDP. That advice is great,
> > but the reasons Section 4.5 discusses are not that strong. The fact tha=
t
> > the linux kernel has improved is irrelevant if an operator uses
> > non-linux boxes. Also, an operator using UDP over IPsec, for instance,
> > will not face the problems described there. The main recommendation in
> > Section 4.5 seems to actually be to use an integrity protection
> > mechanism. Clarifying that section would be useful.
> >
> > [refs.sbcfuncs] has been published as RFC 5853
> >
> > A few references only include the title and the author fields. Adding
> > the venue where they were published would be useful.
> >
>=20
> _______________________________________________
> Speermint mailing list
> Speermint@ietf.org
> https://www.ietf.org/mailman/listinfo/speermint

From gonzalo.camarillo@ericsson.com  Wed Jan 26 23:23:06 2011
Return-Path: <gonzalo.camarillo@ericsson.com>
X-Original-To: speermint@core3.amsl.com
Delivered-To: speermint@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 220F73A6B0B for <speermint@core3.amsl.com>; Wed, 26 Jan 2011 23:23:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.632
X-Spam-Level: 
X-Spam-Status: No, score=-106.632 tagged_above=-999 required=5 tests=[AWL=-0.033, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SAwmcwGCFxZH for <speermint@core3.amsl.com>; Wed, 26 Jan 2011 23:23:05 -0800 (PST)
Received: from mailgw10.se.ericsson.net (mailgw10.se.ericsson.net [193.180.251.61]) by core3.amsl.com (Postfix) with ESMTP id 9CC263A6B02 for <speermint@ietf.org>; Wed, 26 Jan 2011 23:23:04 -0800 (PST)
X-AuditID: c1b4fb3d-b7b89ae0000036a3-a3-4d411e0e4891
Received: from esessmw0197.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw10.se.ericsson.net (Symantec Mail Security) with SMTP id 51.B0.13987.E0E114D4; Thu, 27 Jan 2011 08:26:06 +0100 (CET)
Received: from [131.160.126.208] (153.88.115.8) by esessmw0197.eemea.ericsson.se (153.88.115.88) with Microsoft SMTP Server id 8.2.234.1; Thu, 27 Jan 2011 08:26:06 +0100
Message-ID: <4D411E0E.6020208@ericsson.com>
Date: Thu, 27 Jan 2011 09:26:06 +0200
From: Gonzalo Camarillo <Gonzalo.Camarillo@ericsson.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: speermint@ietf.org
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: AAAAAA==
Subject: [Speermint] Fwd: opsdir review of draft-ietf-speermint-architecture-17.txt
X-BeenThere: speermint@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the speermint working group <speermint.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speermint>
List-Post: <mailto:speermint@ietf.org>
List-Help: <mailto:speermint-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speermint>, <mailto:speermint-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Jan 2011 07:23:06 -0000

Hi,

please, note the following review on the general IETF list. The IESG
will be discussing this draft on February 3rd.

Cheers,

Gonzalo

-------- Original Message --------
Subject: opsdir review of draft-ietf-speermint-architecture-17.txt
Date: Tue, 25 Jan 2011 17:38:05 +0100
From: Bert (IETF) Wijnen <bertietf@bwijnen.net>
To: Jason_Livingood@cable.comcast.com
<Jason_Livingood@cable.comcast.com>,	d.malas@cablelabs.com
<d.malas@cablelabs.com>
CC: ops-dir@ietf.org <ops-dir@ietf.org>, ietf@ietf.org >>
"ietf@ietf.org" <ietf@ietf.org>

I was appointed to review this document from an OPS-DIR point of
vie, i,e, to check for operational or management aspects.

This are is not my space of expertise, so don't rely too much on my
report.

I think that there might be some operational aspects in the sense that
sometimes secure/encrypted connections are needed and other times it may be
OK to use unencrypted connections if they are inside the same secure
building.
So is there not something for an operator to configure in such cases?

typo:

Section 4, 4th bullet, 2nd sub bullet:

       *  LUF can communicator with SF and SBE

     s/cator/cate/

Section 5.1.1.2 2nd para:

    If an im: or pres: URI is chosen based on an "E2U+im" [RFC3861] or
    "E2U+pres" [RFC3953] enumserver, the SSP follows the procedures for
    resolving these URIs to URIs for specific protocols such a SIP or
    XMPP as described in the previous section.

    s/such a SIP/such as SIP/

Bert Wijnen


_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www.ietf.org/mailman/listinfo/ietf

