Re: Version 2 of CPIM Subscription Data Format
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
With my tail firmly placed between my legs, I humbly admit I failed to include a "Security Considerations" section in Version 2 of CPIM Subscription Data Format. Enclosed is the missing text. 6. Security Considerations The CPIM Subscription Data Format (SDF) provides a PRESENCE SERVICE means of identifying and authenticating the SUBSCRIBER that is requesting presence service using digital signatures. The use of both digital signatures and the Subscription Data Format provides a protocol with a strong mechanism to meet the requirement for authentication stated in [RFC2779, Section 5.1.12]. Failure to provide some mechanism to authenticate subscription requests makes a PRESENCE SERVICE vulnerable to being spoofed by a SUBSCRIBER. A PRESENCE SERVICE MAY make access control decisions based on the presence URI in the From field of a subscription request, and the existence of a valid signature. To ensure that the From field identifies the signer, a signed request SHOULD include a certificate that binds it to the presence URI in the From field. For example, when using X.509 Version 3 Certificates [X.509V3], the presence URI in the From field SHOULD be one of the certificate's Subject Alternate Names. .... [ Added Reference ] [X.509V3] R. Housley, W. Polk, W. Ford, and D. Solo, "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile", RFC 3280, April 2002. .... John [reminder: [email protected] for non-technical discussions, please]