RE: Sub/Not Security, Presence service identifiers

"Peterson, Jon" <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
It isn't clear to me why the need for a timestamp in notifications wouldn't
motivate us to provide a timestamp capability within PIDF, rather than
requiring a wrapper for notifications. At least, I would think the timestamp
should be created at the same time as the rest of the presence information,
and that it should be managed under the same security properties as the rest
of the presence information.

Was there some reason that a wrapper seemed more attractive? Especially
considering that a <timestamp> element is defined in PIDF? 

Jon Peterson
NeuStar, Inc.

> -----Original Message-----
> From: [email protected] [mailto:[email protected]]
> Sent: Monday, August 19, 2002 7:15 AM
> To: Peterson, Jon
> Cc: '[email protected]'
> Subject: Re: Sub/Not Security, Presence service identifiers
> 
> 
> "Peterson, Jon" <[email protected]> writes:
> 
> > The way the presence service identifier issue was raised in Yokohama
> > (following the list mail) was as follows:
> > 
> > 7. A wrapper for presence information be defined that 
> contains a name
> >    that identifies a presence service, and nothing else.
> > 
> > That was the idea that was opposed there - I imagine you 
> agree that we don't
> > need one or those?
> 
> I realize I have been under the mistaken impression that since the
> group has decided to address the issue of authentication of
> notifications, as required in RFC 2779, it has also agreed to adding a
> wrapper for presence information.  The reason I made this mistaken
> assumption is I saw no other way to add timestamp information, which
> is required to thwart replay attacks.  Once you have a wrapper, it
> seems that the most obvious way to specify a timestamp is to use the
> syntax used by instant messages.  One you do that, you might as well
> add a 'From' header as defined in instant messages so that one can
> reuse the authentication software for instant messages unchanged.  As
> Jon point's out, you don't need to put the presence service identifier
> in a wrapper as long as it can be computed from something about the
> presence notification.  The point of putting it in the wrapper is that
> the protocol becomes simple and regular.
> 
> Given the need for a timestamp, are people still opposed to a wrapper
> for presence information?
> 
> John
> 
> 
> 
>   [reminder: [email protected] for non-technical 
> discussions, please]
> 



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.