Re: RE: [Geopriv] Consensus on changes to location-conveyance

Andrew Newton <[email protected]>
Newsgroups gmane.ietf.sip,gmane.ietf.geopriv
Message-ID <[email protected]>
On Jul 25, 2006, at 7:21 PM, Jeroen van Bemmel wrote:
> For location-by-reference, you'd probably want some additional  
> requirements:
> - URL must be valid for a limited amount of time
> - URL must be cryptographically hard to guess
> - URL must not contain any information that identifies the user /  
> device / AoR
> - for whatever transport protocol is used: response must be marked  
> as 'no cache'
> - user must be able to remove the information at the URL, ie  
> explicit invalidation
> - user must be able to verify correctness of the issued information  
> (ie user can access the URL himself)
> - user must be able to control who accesses the URL, both upfront  
> and history of accesses (for a reasonable period)
> - there must be explicit consent before a proxy would insert user  
> location

Please tell me that you are merely suggesting guidelines and  
considerations by operators and are not suggesting 2119 language for  
these?  Because just like you'd never get agreement on the intended  
duration or accuracy or confidence of location-by-value, you'd never  
get agreement on these.

> For the latter point: except for emergency scenario's, the UAC  
> should include some flag in the INVITE saying "proxy: please append  
> location". You'd probably also want some feedback (eg proxy or UAS  
> adding a header to the response saying 'this is the URL that I  
> appended/got'

Just thinking out loud here, but maybe the rule should be that  
proxies never append a Location header except for emergencies.

-andy

_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.