RE: Sub/Not Security, Presence service identifiers

"Adrian Bateman" <[email protected]>
Newsgroups gmane.ietf.impp
Organization VisionTech Limited
Message-ID <00f001c247a4$32791580$0201580a@ADRIANXP>
On 19 August 2002 13:12, John D. Ramsdell wrote:
> When receiving a notification, a watcher would like to know that the
> presence service that is sending the notification is authorize to do
> so on behalf of the person that provided presence information.
> Without the authentication of the presence service, a watch could be
> spoofed into receiving presence information from an invalid source.
> 
> Signing the presence information by the person that created it does
> not fix the problem, because a spoofing presence service could collect
> signed presence information and replay them in an order that
> misinforms the watcher.  In addition, in some systems, a presence
> service generates the online information in a presence information
> document based on whether there is an open TCP/IP connection to the
> person's client.  In these systems, only the presence service can sign
> all of the presence information, because the person does not
> contribute the online status elements.  
> 
> One final point, I believe there is an explicit requirement in one of
> the RFC's that says a watcher has to be able to authenticate a
> presence service.  I'm too lazy to look it up now.

Yes, I recognise the need to authenticate things as you say, but I
couldn't find anything in the RFC's related to the presence service. In
particular, there was consensus ages ago that we make sure there wasn't
an advantage in running a local server as opposed to a client - this
says to me that in some situations it would be the client that would
provide presence information.

Presence subscriptions must be authenticated to ensure that only the
right people get to see my presence document. I can create different
presence documents for different subscriptions. I send out notifications
when my presence document changes. One might think that the document
would be created at that time by the client.

If a presence service is in some way responsible for generating my
presence document based on some property such as a TCP/IP connection,
should it not have the responsibility for my presence URI, and hence for
being able to sign on my behalf?

Adrian.
smime.p7s (application/x-pkcs7-signature, 3.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.