[Geopriv] Re: teasing apart: http as a GEOPRIV using protocol
Randall Gellens <[email protected]>
| Newsgroups | gmane.ietf.sip,gmane.ietf.geopriv |
|---|---|
| Message-ID | <p0630000ac0ef1692b321@[192.168.1.13]> |
At 9:33 AM -0400 7/27/06, Henning Schulzrinne wrote:
> For all protocols, the hardest part is specifying how
> authentication works in conjunction with the privacy rules. This is
> far from obvious for HTTP, for example. (Is it the Digest user
> identifier? Can Basic over TLS be used instead? What about
> crypto-random request URIs? Is HTTP ok in that case or is HTTPS
> needed - the answer isn't obvious since an observer would only see
> a location, not a location-identity pair.)
>
> For SIP, this is largely done, except for the crypto-random request
> URI case and variations, such as user + password.
A while back there was some brief discussion in geopriv about using
"pawn ticket" URIs for location information. That is, URLAUTH from
RFC 4467, which is a URL that has been signed by the server and can
be used by the holder to gain access to the information, subject to
expiration time and/or role restrictions. Role restrictions limit
the URL to being used by an entity that is known to the location
server as performing a specified role. Additionally, RFC 4467 allows
all currently-issued URLs to be revoked by changing the key.
I wonder if there is any value in this?
--
Randall Gellens
Opinions are personal; facts are suspect; I speak for myself only
-------------- Randomly-selected tag: ---------------
It wasn't as easy to get programs right as we had thought.
--Wilkes, 1949
_______________________________________________
Sip mailing list https://www1.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip