Re: teasing apart: http as a GEOPRIV using protocol

Henning Schulzrinne <[email protected]>
Newsgroups gmane.ietf.sip,gmane.ietf.geopriv
Message-ID <[email protected]>
For all protocols, the hardest part is specifying how authentication  
works in conjunction with the privacy rules. This is far from obvious  
for HTTP, for example. (Is it the Digest user identifier? Can Basic  
over TLS be used instead? What about crypto-random request URIs? Is  
HTTP ok in that case or is HTTPS needed - the answer isn't obvious  
since an observer would only see a location, not a location-identity  
pair.)

For SIP, this is largely done, except for the crypto-random request  
URI case and variations, such as user + password.

On Jul 27, 2006, at 9:27 AM, Brian Rosen wrote:

> I think HTTP requires some specification.  A raw GET based  
> retrieval of a
> PIDF would be a fairly short RFC, but I think we need that RFC.
>
> While I don't think it's necessary (SIP SUBSCRIBE is sufficient), I  
> don't
> object to defining HTTP as a using protocol in a suitable RFC.
>
> Brian


_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.