Notification authentication -- more things left out of the PIDF draft
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
In a setting in which security is important, one must provide a means for a client that is watching a presence entity to verify that notifications about the presence entity originated at the presence server to which the watcher is subscribed. To allow a notification to be signed, it is important to define a standard way in which PIDF is embedded into CPIM-MSGFMT content, but the most important aspect of this embedding is that the From field identify the server that is sending the notification, and not identify the presence entity that is contained in the content. The From field of a subscription request names a presence entity and identifies the principal that originated the request. If the From field of a notification names a presence entity, than it is erroneously identifying a client as the source of a notification, where as the true originator of the notification is the presence server. Failure to correctly identify the principal of a notification negates the value of using digital signatures for authentication. For more on this topic, see: http://simp.mitre.org/drafts/simp_server.html#security and http://simp.mitre.org/drafts/simp_server.html#notify John [reminder: [email protected] for non-technical discussions, please]