Re: Notification authentication -- more things left out of the PIDF draft
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
"Adrian Bateman" <[email protected]> writes: > The reason for the original wrapping section was so that different ... I understand that the 02 version of the PIDF spec included a wrapping section for purposes other than the one I proposed. I understand and agree with your reasoning as to why that section was omitted from the 03 and 04 version. I am asking that it be added back in to serve a different task, to guard against signed notifications that are issued by principals that are not authorized to distribute presence information. In other words, this is a mechanism that can be used to enforce a form of role based authorization using digital signatures. Think of it this way. If I receive a notification from pres:[email protected] that is signed, I really want to know that the signer is authorized to put the address pres:[email protected] in the 'From' header of a notification, and not some random user within The MITRE Corporation. John [reminder: [email protected] for non-technical discussions, please]