RE: On the need for presence service identifiers

"Adrian Bateman" <[email protected]>
Newsgroups gmane.ietf.impp
Organization VisionTech Limited
Message-ID <00c001c24914$b577dc20$6405010a@ADRIANXP>
On 21 August 2002 12:33, John D. Ramsdell wrote:
> Your insight suggests to me that for subscriptions, a presence service
> should accept a signed request if is signed using the watcher's
> presentity private key (the usual case), or if it is signed by the
> presence service's private key.  In other words, when X.509
> certificates are being used, the subjectAltName must contain either
> the presentity identifier of the watcher, OR the watcher's presence
> service identifier.

This only makes sense if you arrive at the assumption that we do need a
presence service identifier - still not sure that we need that.

> Playing devil's advocate was a good thing.  Now it's my turn.
> 
> One can imagine the same architecture for instant messaging.  If an
> instant messaging service had a identity, it could sign messages
> coming from authenticated sources that are routed through it.  I can
> imagine a site that has single system login by deploying Kerberos.  By
> this I mean, people login once, and every application uses Kerberos to
> acquire a user's credentials.  As a result, a user could create an
> authenticated connection to an instant messaging service without
> exchanging passwords, or instant messaging specific certificates.
> 
> Do we really want to pursue this idea?

Well, this makes the parallel case for instant messaging when compared
to presence. It says that if we have a presence service identifier in
the presence world then we can apply this in the IM world and yes we
could. But my argument is that we don't need this in the IM world and
the parallel case suggests therefore that we don't need it in the
presence world either.

> By the way, Jon Peterson is clearly promoting the idea that the signed
> content of a presence notification need not contain the presence
> service's identifier, since in secure situations, this identifier
> would be in the subjectAltName of the X.509 V3 Certificate, and
> otherwise could be forged.  What do you think of this idea?  It
> certainly works in environments that use X.509 Version 3 Certificates.

I don't know much about X.509 - I read Jon's main point as being that
the case for a presence service identifier isn't yet proven and his
seems like a compelling argument. His suggestion that having the
timestamp at the point when the document is generated guarantees that it
was valid at that time is clear. I don't think there was a requirement
to guarantee that watchers definitely receive notifications so a third
party could certainly stop presence updates getting through anyway. But
the fact that they couldn't be forged is the important thing. That
satisfies 2779/5.2.4.

Adrian.
smime.p7s (application/x-pkcs7-signature, 3.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.