[Geopriv] Re: teasing apart: http as a GEOPRIV using protocol

Randall Gellens <[email protected]>
Newsgroups gmane.ietf.sip,gmane.ietf.geopriv
Message-ID <p0630000ac0ef1692b321@[192.168.1.13]>
At 9:33 AM -0400 7/27/06, Henning Schulzrinne wrote:

>  For all protocols, the hardest part is specifying how 
> authentication works in conjunction with the privacy rules. This is 
> far from obvious for HTTP, for example. (Is it the Digest user 
> identifier? Can Basic over TLS be used instead? What about 
> crypto-random request URIs? Is HTTP ok in that case or is HTTPS 
> needed - the answer isn't obvious since an observer would only see 
> a location, not a location-identity pair.)
>
>  For SIP, this is largely done, except for the crypto-random request 
> URI case and variations, such as user + password.

A while back there was some brief discussion in geopriv about using 
"pawn ticket" URIs for location information.  That is, URLAUTH from 
RFC 4467, which is a URL that has been signed by the server and can 
be used by the holder to gain access to the information, subject to 
expiration time and/or role restrictions.  Role restrictions limit 
the URL to being used by an entity that is known to the location 
server as performing a specified role.  Additionally, RFC 4467 allows 
all currently-issued URLs to be revoked by changing the key.

I wonder if there is any value in this?
-- 
Randall Gellens
Opinions are personal;    facts are suspect;    I speak for myself only
-------------- Randomly-selected tag: ---------------
It wasn't as easy to get programs right as we had thought.
                                           --Wilkes, 1949

_______________________________________________
Sip mailing list  https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.