Re: [AVTCORE] Roman Danyliw's No Objection on draft-ietf-payload-tsvcis-03: (with COMMENT)
"Roni Even (A)" <[email protected]>
| Newsgroups | gmane.ietf.avt |
|---|---|
| Message-ID | <6E58094ECC8D8344914996DAD28F1CCD23D78E68@DGGEMM506-MBX.china.huawei.com> |
Hi, Section 8, Per “Applications SHOULD use one or more appropriate strong security mechanisms”, what exactly is the “SHOULD” requiring? As discussed in RFC7201 RTP is used in different application scenarios, as such RTP cannot mandate to the application (for example, SIP, WEBRTC, RTSP,...) which security mechanism to use if at all. We can only say that the application SHOULS use . Note that in some cases the security is not done by the application by its infrastructure (tunnels, ...) Roni Even -----Original Message----- From: Roman Danyliw via Datatracker [mailto:[email protected]] Sent: Tuesday, October 01, 2019 5:03 PM To: The IESG Cc: [email protected]; Ali Begen; [email protected]; [email protected]; [email protected] Subject: Roman Danyliw's No Objection on draft-ietf-payload-tsvcis-03: (with COMMENT) Roman Danyliw has entered the following ballot position for draft-ietf-payload-tsvcis-03: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html for more information about IESG DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-payload-tsvcis/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Section 2. Per “In most IP-based network deployments, standard link encryption methods (SRTP , VPNs, FIPS 140 link encryptors or Type 1 Ethernet encryptors) would be used to secure the RTP speech contents.”, the inclusion of STRP in this list of “link encryption” methods was surprising. The other methods typically provide a service agnostic tunnel but STRP is application specific (and doesn’t protect a link). Section 8, Per “Applications SHOULD use one or more appropriate strong security mechanisms”, what exactly is the “SHOULD” requiring? _______________________________________________ Audio/Video Transport Core Maintenance [email protected] https://www.ietf.org/mailman/listinfo/avt