Re: Authenticated subscription request

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
It appears from the lack of responses to my original posting on this
subject, that the current standard provides no common format for
subscription requests, and therefore provides no means for
authenticating subscription requests sent through IMPP compliant
gateways.  

Please help me define a common subscription request format that best
captures the spirit of the IMPP community, and thus has the best
prospect of being used by protocols likely to be transported by an
IMPP compliant gateway.

Surely, the format should use the CPIM Message Format, with the To
field naming the presentity which is the target of the subscription
request, the DateTime field dating the request, and the From field
both identifying the originator of the request and the address to
which notifications should be sent.  My question to you is how should
the request duration information be transported?  Here are two
possibilities:

1.  The duration is transported as a required field.  With this
    assumption, a subscription request might look like:

    Content-type: Message/CPIM

    To: <pres:[email protected]>
    From: <pres:[email protected]>
    DataTime: 2002-04-04T13:40:00-08:00
    NS: <urn:mitre:params:cpim-duration-header:>
    Require Duration
    Duration: 3600

2.  The duration is transported as content using the MIME type
    application/cpim-subscribe, where the content is the time in
    seconds of the requested subscription duration.  In this case, a
    request would look like:

    Content-type: Message/CPIM

    To: <pres:[email protected]>
    From: <pres:[email protected]>
    DataTime: 2002-04-04T13:40:00-08:00
    Content-type: application/cpim-subscribe

    3600

Which is best?  The second option uses a smaller number of bytes.

John

[email protected] (John D. Ramsdell) writes:

> >From the cpim-msgfmt document, it is obvious how to post an
> authenticated message request.  The document includes this case as an
> example.  For presence, it is obvious how to send an authenticated
> notification because presence information can be sent using the
> cpim-msgfmt, and the presence format is defined in cpim-pidf.
> 
> How does one send an authenticated subscription request?  I studied
> the following documents, but was unable to find the answer to my
> question.
> 
> draft-ietf-impp-cpim-02.txt	    draft-ietf-impp-cpim-pidf-02.txt
> draft-ietf-impp-cpim-msgfmt-06.txt  draft-ietf-impp-datetime-05.txt
> 
> Since many users will want to control the access of presence
> information, it is essential that a mechanism be provided that allows
> a user to authenticate the source of a subscription request.
> 
> John
> 
> 
>   [reminder: [email protected] for non-technical discussions, please]
> 

-- 
Please avoid sending me Word or PowerPoint attachments.
See http://www.fsf.org/philosophy/no-word-attachments.html


  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.