Re: Definition of the pres: URI in impp-pres-01
Derek Atkins <[email protected]> 23 Jan 2003 01:02:25 -0500
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
Jonathan Rosenberg <[email protected]> writes: > >>Secondly is authorization. What if the presentity wishes for one of > >>those watchers to receive the presence document, but not others? Or, > > The presentity includes the list of the watchers in the message, so > > it > > can say which watchers should get the message. If you want these five > > watchers to get it and those other five not, then you only include the > > former in the "to" field. > > That is assuming substantial trust between domains. I dont think you > could normally assume this. Well, no -- because you encrypt the message only to those five recipients as I previously suggested. There is no trust required of the other system (except trusting that it wont drop the message on the floor -- but you have to trust that anyways). > Definitely. SIMPLE is actively working on filters that would allow the > watcher to ask for a subset of the presence state. Its common when the > subscriber is an application and only interested in a particular piece > of presence state. Well, sure, but that's a VERY different issue than the PRESENTITY trying to send different data to different watchers. If the watcher gets more info than it cares about it can just ignore the extraneous stuff. That's not a threat. The threat is when it's the other way around and the presentity wants to limit the data.... > >>A problem, yes. It is definitely something you need to help > >>scalability in very large systems. But, its significant security > >>implications imply its usage in very specific situations where there > >>is strong trust between the two domains. I do not think it is ever > >>practical in the inter-domain case you describe above. > > I'm not so sure. I think it works fine in MOST situations, even with > > end-to-end security requirements... Except in the case where you want > > to send "different" presence documents to different people. In that > > case you need to send multiple documents, so you may as well send > > multiple messages. However, I still believe that the "normal" case is > > sending the same document to all your watchers. > > There is a serious issue of trust, which I point out above. THe > presentity needs to trust the watcher domain to only distribute the > presence document to the list of people specified in the To field. As I said, you just encrypt the document to the intended recipients and you're done. See above. > >>Even if it was practical, it certainly seems like something which is > >>beyond the 'baseline' model we have been following for CPIM/CPP all > >>along. > > *sigh* Yes, I know. > > Well, in that case, can we consider this issue closed as far as the > specs are concerned? Unless there is a real issue here, I'd say yes, consider it closed. I'd like to see the specs finished. We can always work on IMPP-BIS and re-open the discussion... > -Jonathan R. -derek -- Derek Atkins Computer and Internet Security Consultant [email protected] www.ihtfp.com [reminder: [email protected] for non-technical discussions, please]