Re: Sub/Not Security, Presence service identifiers

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
"Peterson, Jon" <[email protected]> writes:

> The way the presence service identifier issue was raised in Yokohama
> (following the list mail) was as follows:
> 
> 7. A wrapper for presence information be defined that contains a name
>    that identifies a presence service, and nothing else.
> 
> That was the idea that was opposed there - I imagine you agree that we don't
> need one or those?

I realize I have been under the mistaken impression that since the
group has decided to address the issue of authentication of
notifications, as required in RFC 2779, it has also agreed to adding a
wrapper for presence information.  The reason I made this mistaken
assumption is I saw no other way to add timestamp information, which
is required to thwart replay attacks.  Once you have a wrapper, it
seems that the most obvious way to specify a timestamp is to use the
syntax used by instant messages.  One you do that, you might as well
add a 'From' header as defined in instant messages so that one can
reuse the authentication software for instant messages unchanged.  As
Jon point's out, you don't need to put the presence service identifier
in a wrapper as long as it can be computed from something about the
presence notification.  The point of putting it in the wrapper is that
the protocol becomes simple and regular.

Given the need for a timestamp, are people still opposed to a wrapper
for presence information?

John



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.