RE: [Geopriv] Explicit Indication of Location Object Consumer
"Brian Rosen" <[email protected]>
| Newsgroups | gmane.ietf.sip,gmane.ietf.geopriv |
|---|---|
| Message-ID | <[email protected]> |
My outbound proxy doesn't do location based routing (although some may do so for emergency calls). It will ignore it, because it doesn't do location based routing, as will any proxy in the path. The one that does (pizza-hut.com) knows to do location based routing, because that is what it's supposed to do to resolve [email protected]. I'm trying to stay within the geopriv rules. They require that the LO be protected from unauthorized entities learning the location. With SIP, we have hop-by-hop security mechanisms (TLS) and we have end-to-end mechanisms (S/MIME). If I want routing based on location, then proxies are authorized to see location, and, really, I don't know which proxy is doing it. I could use "end to middle" security I suppose, if I knew which element was doing the routing. We could look at that, but I'm reluctant to get into it. Unless you want to propose some new security mechanism just for this header, TLS and S/MIME are all there is, and I would say we should specify TLS if the location is to be used for routing a call, and S/MIME if it is for use only by the endpoint. I think those are SHOULDs, not MUSTs, as long as we can meet the requirements of 3693. Brian > -----Original Message----- > From: Hannes Tschofenig [mailto:[email protected]] > Sent: Monday, May 22, 2006 3:56 PM > To: Brian Rosen > Cc: 'Tschofenig, Hannes'; [email protected]; [email protected] > Subject: Re: [Geopriv] Explicit Indication of Location Object Consumer > > Hi Brian, > > Brian Rosen wrote: > > I don't see this as a problem. > > > > Let's take the non-emergency case. > > > > If I call [email protected], and I want location based routing, I > put > > my location header in the call, and send the call with TLS. My outbound > > proxy will properly ignore it. > > Why do you expect the outbound proxy to ignore it? > > The pizza-hut domain is the one that wants > > to do location based routing, it will get the location and send it off. > I > > don't need to tell it to do that. I could imagine a generic location > based > > routing proxy, but I would not think we would want to mark the location > > header as the way to get it invoked; we need something else (directly, > or > > indirectly, a Route header) to do that. > > > > If I want the endpoint to get it, then I protect it with S/MIME and no > proxy > > sees it. > > I can buy the remark by James that you would put the location object > into the body to tell the proxy not to look at it. > > S/MIME is nice; but maybe it is not always available. > > Ciao > Hannes > > > > > Brian > > > > -----Original Message----- > > From: Tschofenig, Hannes [mailto:[email protected]] > > Sent: Monday, May 22, 2006 10:54 AM > > To: Brian Rosen; Hannes Tschofenig; [email protected]; [email protected] > > Subject: AW: [Geopriv] Explicit Indication of Location Object Consumer > > > > Hi Brian, > > > > > >>I would say no. If the location is not needed by proxies, > >>then I would say > >>you MUST protect it (S/MIME), or it will not be private. > > > > I am less concerned about the security aspects here and more focused the > > protocol operation first. > > Typically, it is good to know for a device whether it has to process the > > content of the message or not. > > > > If you want to prevent intermediaries to inspect your location object > > then S/MIME might be a choice (at least on paper). > > > > > >>If you have to route on it (emergency or otherwise), then you > >>have to send > >>it with TLS, and the proxies can see it. > >> > >>Brian > > > > > > Ciao > > Hannes > > > > > >>-----Original Message----- > >>From: Hannes Tschofenig [mailto:[email protected]] > >>Sent: Sunday, May 21, 2006 7:40 AM > >>To: [email protected]; [email protected] > >>Subject: [Geopriv] Explicit Indication of Location Object Consumer > >> > >>Hi James > >>Hi Brian, > >> > >>do you plan to put additional info into the SIP message to > >>indicate who > >>should consume the Location Object (explicity rather than > >>implicit info)? > >> > >>Here is an example: Assume that SIP UA Alice wants to give > >>Bob location > >>information (via reference). Now, Alice could easily indicate that it > >>wants Bob to resolve the reference and to process the > >>location object. > >>Stating this explicitly would prevent proxies to resolve it and to > >>process the location object. > >> > >>Ciao > >>Hannes > >> > >> > >>_______________________________________________ > >>Geopriv mailing list > >>[email protected] > >>https://www1.ietf.org/mailman/listinfo/geopriv > >> > >> > >>_______________________________________________ > >>Geopriv mailing list > >>[email protected] > >>https://www1.ietf.org/mailman/listinfo/geopriv > >> > > > > > > _______________________________________________ Sip mailing list https://www1.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use [email protected] for questions on current sip Use [email protected] for new developments on the application of sip