Re: teasing apart: http as a GEOPRIV using protocol
Henning Schulzrinne <[email protected]>
| Newsgroups | gmane.ietf.sip,gmane.ietf.geopriv |
|---|---|
| Message-ID | <[email protected]> |
For all protocols, the hardest part is specifying how authentication works in conjunction with the privacy rules. This is far from obvious for HTTP, for example. (Is it the Digest user identifier? Can Basic over TLS be used instead? What about crypto-random request URIs? Is HTTP ok in that case or is HTTPS needed - the answer isn't obvious since an observer would only see a location, not a location-identity pair.) For SIP, this is largely done, except for the crypto-random request URI case and variations, such as user + password. On Jul 27, 2006, at 9:27 AM, Brian Rosen wrote: > I think HTTP requires some specification. A raw GET based > retrieval of a > PIDF would be a fairly short RFC, but I think we need that RFC. > > While I don't think it's necessary (SIP SUBSCRIBE is sufficient), I > don't > object to defining HTTP as a using protocol in a suitable RFC. > > Brian _______________________________________________ Sip mailing list https://www1.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use [email protected] for questions on current sip Use [email protected] for new developments on the application of sip