Re: Definition of the pres: URI in impp-pres-01

Jonathan Rosenberg <[email protected]> Thu, 23 Jan 2003 00:23:03 -0500
Newsgroups gmane.ietf.impp
Organization dynamicsoft
Message-ID <[email protected]>
more inline.

Derek Atkins wrote:
> This is getting off topic, but...
> 
> Jonathan Rosenberg <[email protected]> writes:
> 
> 
>>Well, there are many tricky issues lurking in such a solution.
>>
>>First and foremost is security. If we want to provide end-to-end
>>encryption of the presence document, how would that be done? Would we
>>need to somehow create and manage group shared keys? Egads! Would you
>>need to encrypt it N times, one for each watcher? That defeats the
>>purpose of your mechanism. Would we need to forsake e2e security? I
>>hope not.
> 
> 
> You could encrypt it the PGP way.  You create a random session key,
> encrypt the presence document in that key, then you encrypt the
> session key for each recipient.

I think that would work. But, its pretty far from the baseline operation 
described in CPP.


> 
> 
>>Secondly is authorization. What if the presentity wishes for one of
>>those watchers to receive the presence document, but not others? Or,
> 
> 
> The presentity includes the list of the watchers in the message, so it
> can say which watchers should get the message.  If you want these five
> watchers to get it and those other five not, then you only include the
> former in the "to" field.

That is assuming substantial trust between domains. I dont think you 
could normally assume this.

> 
> 
>>if it wishes for one of them to receive one subset of the presence
>>information, and another to receive a different subset?
> 
> 
> _THIS_ is certainly a troublesome issue.  Is this actually done
> in real systems?  I can understand the theoretical nature of
> the question.

Definitely. SIMPLE is actively working on filters that would allow the 
watcher to ask for a subset of the presence state. Its common when the 
subscriber is an application and only interested in a particular piece 
of presence state.

>>A problem, yes. It is definitely something you need to help
>>scalability in very large systems. But, its significant security
>>implications imply its usage in very specific situations where there
>>is strong trust between the two domains. I do not think it is ever
>>practical in the inter-domain case you describe above.
> 
> 
> I'm not so sure.  I think it works fine in MOST situations, even with
> end-to-end security requirements...  Except in the case where you want
> to send "different" presence documents to different people.  In that
> case you need to send multiple documents, so you may as well send
> multiple messages.  However, I still believe that the "normal" case is
> sending the same document to all your watchers.

There is a serious issue of trust, which I point out above. THe 
presentity needs to trust the watcher domain to only distribute the 
presence document to the list of people specified in the To field.


> 
> 
>>Even if it was practical, it certainly seems like something which is
>>beyond the 'baseline' model we have been following for CPIM/CPP all
>>along.
> 
> 
> *sigh*  Yes, I know.

Well, in that case, can we consider this issue closed as far as the 
specs are concerned?

-Jonathan R.


-- 
Jonathan D. Rosenberg, Ph.D.                72 Eagle Rock Ave.
Chief Scientist                             First Floor
dynamicsoft                                 East Hanover, NJ 07936
[email protected]                     FAX:   (973) 952-5050
http://www.jdrosen.net                      PHONE: (973) 952-5000
http://www.dynamicsoft.com




  [reminder: [email protected] for non-technical discussions, please]