Re: Sub/Not Security, Presence service identifiers

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
"Peterson, Jon" <[email protected]> writes:

> Actually, I'm not sure this is true. The presence information could be
> signed by the presentity. If so, it's irrelevant how the signed presence
> information is transported to the watcher, provided it is
> transported intact

I completely disagree with this analysis.  Let's look at the
requirement.

5.2.4 of RFC2779 says

   The protocol MUST provide means of protecting B from another
   PRINCIPAL C "spoofing" notification messages about B.

The requirement is about giving B the means to distinguish between
notification messages sent by authoritative sources from those sent by
non-authoritative sources.  The path by which the presence information
is relevant.  In particular, a bad guy can take perfectly good
presence information, and spoof B by delaying and/or changing the order
of delivery of presence information.

Jon, I updated my example on the need for presence service identifiers
and set it to the list.  See if that helps you decide who must sign
presence notifications.

John



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.