Re: Sub/Not Security, Presence service identifiers
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
"Mark Day" <[email protected]> writes: > > Presence information could have been generated a week ago because > > I went on holiday and haven't updated my presence info from > > saying "On holiday". You subscribe to my presence info today. You > > get a week old presence info. Does that mean my presence info > > cannot be authentic? > > > > Timestamp of when the notification is sent makes more sense to me. > > It's OK to have a timestamp for when a notification is sent. The question is > whether the notification including that timestamp has to be signed by the > presence service, so as to prove that the timestamp is correct. Actually, the question is not whether the timestamp must be signed, but whether some presence services are allowed to sign this information. I, in no way, think that all presence information that is signed must include the time at which the notification request delivering it was initiated. This would prevent people from signing the content. All I ask is that some implementations of presence services be allowed to sign and timestamp presence information when a notification request is made. You comments suggests to me we can find something to agree on. Does every one think that notification requests should be timestamped? An answer of yes implies nothing about whether you think the timestamp should be signed. My answer is definitely yes. John [reminder: [email protected] for non-technical discussions, please]