Re: Version 2 of CPIM Subscription Data Format

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
With my tail firmly placed between my legs, I humbly admit I failed to
include a "Security Considerations" section in Version 2 of CPIM
Subscription Data Format.  Enclosed is the missing text.

6. Security Considerations

The CPIM Subscription Data Format (SDF) provides a PRESENCE SERVICE
means of identifying and authenticating the SUBSCRIBER that is
requesting presence service using digital signatures.  The use of both
digital signatures and the Subscription Data Format provides a protocol
with a strong mechanism to meet the requirement for authentication
stated in [RFC2779, Section 5.1.12].  Failure to provide some mechanism
to authenticate subscription requests makes a PRESENCE SERVICE
vulnerable to being spoofed by a SUBSCRIBER.

A PRESENCE SERVICE MAY make access control decisions based on the
presence URI in the From field of a subscription request, and the
existence of a valid signature.  To ensure that the From field
identifies the signer, a signed request SHOULD include a certificate
that binds it to the presence URI in the From field.  For example, when
using X.509 Version 3 Certificates [X.509V3], the presence URI in the
From field SHOULD be one of the certificate's Subject Alternate Names.

.... [ Added Reference ]


[X.509V3]
   R. Housley, W. Polk, W. Ford, and D. Solo, "Internet X.509 Public Key
   Infrastructure Certificate and Certificate Revocation List (CRL)
   Profile", RFC 3280, April 2002.

....

John



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.