Re: Definition of the pres: URI in impp-pres-01
Jonathan Rosenberg <[email protected]> Thu, 23 Jan 2003 00:23:03 -0500
| Newsgroups | gmane.ietf.impp |
|---|---|
| Organization | dynamicsoft |
| Message-ID | <[email protected]> |
more inline. Derek Atkins wrote: > This is getting off topic, but... > > Jonathan Rosenberg <[email protected]> writes: > > >>Well, there are many tricky issues lurking in such a solution. >> >>First and foremost is security. If we want to provide end-to-end >>encryption of the presence document, how would that be done? Would we >>need to somehow create and manage group shared keys? Egads! Would you >>need to encrypt it N times, one for each watcher? That defeats the >>purpose of your mechanism. Would we need to forsake e2e security? I >>hope not. > > > You could encrypt it the PGP way. You create a random session key, > encrypt the presence document in that key, then you encrypt the > session key for each recipient. I think that would work. But, its pretty far from the baseline operation described in CPP. > > >>Secondly is authorization. What if the presentity wishes for one of >>those watchers to receive the presence document, but not others? Or, > > > The presentity includes the list of the watchers in the message, so it > can say which watchers should get the message. If you want these five > watchers to get it and those other five not, then you only include the > former in the "to" field. That is assuming substantial trust between domains. I dont think you could normally assume this. > > >>if it wishes for one of them to receive one subset of the presence >>information, and another to receive a different subset? > > > _THIS_ is certainly a troublesome issue. Is this actually done > in real systems? I can understand the theoretical nature of > the question. Definitely. SIMPLE is actively working on filters that would allow the watcher to ask for a subset of the presence state. Its common when the subscriber is an application and only interested in a particular piece of presence state. >>A problem, yes. It is definitely something you need to help >>scalability in very large systems. But, its significant security >>implications imply its usage in very specific situations where there >>is strong trust between the two domains. I do not think it is ever >>practical in the inter-domain case you describe above. > > > I'm not so sure. I think it works fine in MOST situations, even with > end-to-end security requirements... Except in the case where you want > to send "different" presence documents to different people. In that > case you need to send multiple documents, so you may as well send > multiple messages. However, I still believe that the "normal" case is > sending the same document to all your watchers. There is a serious issue of trust, which I point out above. THe presentity needs to trust the watcher domain to only distribute the presence document to the list of people specified in the To field. > > >>Even if it was practical, it certainly seems like something which is >>beyond the 'baseline' model we have been following for CPIM/CPP all >>along. > > > *sigh* Yes, I know. Well, in that case, can we consider this issue closed as far as the specs are concerned? -Jonathan R. -- Jonathan D. Rosenberg, Ph.D. 72 Eagle Rock Ave. Chief Scientist First Floor dynamicsoft East Hanover, NJ 07936 [email protected] FAX: (973) 952-5050 http://www.jdrosen.net PHONE: (973) 952-5000 http://www.dynamicsoft.com [reminder: [email protected] for non-technical discussions, please]