Re: Authenticated subscription request
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
"Mark Day" <[email protected]> writes: > The mailing list is not a very good way of designing something. It would be > more helpful if you could write up and submit a whole draft describing what > you want to accomplish and your proposed mechanism(s). I have made the current draft of the SIMP/2.0 Server Protocol available at the URL: http://simp.mitre.org/drafts/simp_server.html Let be describe how to read this document if your focus is on how it allows IMPP compliant systems to meet the following requirement from RFC2779. 5.1. Requirements related to SUBSCRIPTIONS When A establishes a SUBSCRIPTION to B's PRESENCE INFORMATION: ... 5.1.12. The protocol MUST provide B means of identifying and authenticating the SUBSCRIBER's PRINCIPAL, A. First, read the section titled "Security Considerations" http://simp.mitre.org/drafts/simp_server.html#security followed by the section titled "Subscribe Method". http://simp.mitre.org/drafts/simp_server.html#subscribe I am unsure how to directly respond to your request. I am willing to extract the material related to subscription interoperability into a document that describes a common format for subscription requests. The use of a common format would allow signed subscription requests to be exchanged through gateways. This document would be the analog of the CPIM-PIDF. Of course, it would be a much smaller and simpler document. Alternatively, you may simply be asking me to submit an complete, stand alone email to this list describing the problem and the proposed solution. Since the second interpretation of your request is easier, I'll work on that one until I hear otherwise. John [reminder: [email protected] for non-technical discussions, please]