RE: Notification authentication -- more things left out of the PIDF draft

"Adrian Bateman" <[email protected]>
Newsgroups gmane.ietf.impp
Organization VisionTech Limited
Message-ID <000201c1fde6$b4409000$6405010a@ADRIANXP>
On 17 May 2002 21:01, John D. Ramsdell wrote:
> "Adrian Bateman" <[email protected]> writes:
> 
> > The reason for the original wrapping section was so that different
> ...
> 
> I understand that the 02 version of the PIDF spec included a wrapping 
> section for purposes other than the one I proposed.  I understand and 
> agree with your reasoning as to why that section was omitted from the 
> 03 and 04 version.  I am asking that it be added back in to serve a 
> different task, to guard against signed notifications that are issued 
> by principals that are not authorized to distribute presence 
> information. In other words, this is a mechanism that can be used to 
> enforce a form of role based authorization using digital signatures.
> 
> Think of it this way.  If I receive a notification from 
> pres:[email protected] that is signed, I really want to know that 
> the signer is authorized to put the address pres:[email protected]

> in the 'From' header of a notification, and not some random user 
> within The MITRE Corporation.

The PIDF XML document doesn't have a 'From' header - I think the issue
you are describing is a protocol one, not a data format one. I'm not
saying it doesn't need to be considered, but that it should be part of
the protocol that deals with transmitting the presence data documents
themselves (and in our context therefor, probably in CPIM too).

Adrian.




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.