Mix of TCP and TLS in draft-rosenberg-midcom-turn-07.txt

Remi Denis-Courmont <[email protected]> Tue, 12 Jul 2005 15:44:17 +0300
Newsgroups gmane.ietf.midcom
Organization Nokia-NRC/Helsinki
Message-ID <[email protected]>
	Hello,


Section 8.3 of the latest TURN draft says that any Allocate Request
should be sent to the same IP and port than the Shared Secret Request
from which the one-time credentials where obtained. However, the latter
is sent over TLS, presumably TLS over TCP. Maybe I got it wrong, but it
is my understanding that Allocate Requests should be sent over TCP, ie.
unencrypted TCP, without TLS.

Yet, the draft doesn't how the server can discriminate between TLS
traffic and non-TLS traffic. If the same port is to be used, I believe
some kind of mechanism has to be used to differenciate both properly.

Or maybe, all of the TCP traffic is to be sent over TLS between the TURN
client and the TURN server, but it sounds like that would add some
unneeded computational overhead.

So how is that supposed to be handled ?

Thanks in advance.

Regards,

-- 
Remi Denis-Courmont <[email protected]>
Nokia-NRC/Helsinki