Re: [rtcweb] BUNDLE: Attempting to resolve security consideration
Magnus Westerlund <[email protected]>
| Newsgroups | gmane.ietf.mmusic |
|---|---|
| Message-ID | <[email protected]> |
Hi, I have created a PR for the proposed update of the security consideration text. https://github.com/cdh4u/draft-sdp-bundle/pull/30 Cheers Magnus Den 2017-03-26 kl. 13:41, skrev Magnus Westerlund: > Hi, > > I have attempted to address the issue discussed below by reformulating > that paragraph to read: > > When the BUNDLE extension is used, the set of configurations of the > security mechanism used in all the bundled media descriptions will > need to be compatible for simultaneously use, at least per direction > or endpoint. When using SRTP this will be the case, at least for the > IETF defined key-management solutions due to their SDP attributes > (a=crypto, a=fingerprint, a=mikey) and their classification in > [I-D.ietf-mmusic-sdp-mux-attributes]. > > > So, does this work? > > Cheers > > Magnus > > > Den 2017-03-14 kl. 03:47, skrev Magnus Westerlund: >> Den 2017-03-10 kl. 16:31, skrev Eric Rescorla: >>> >>> When the BUNDLE extension is used, a single set of security >>> credentials over the bundled media descriptions will need to be >>> used, >>> at least per direction or endpoint. >>> >>> >>> Actually, why does this have to be the case? I mean, we require it, but >>> if you have the MID extension, you could easily not do this. >>> >> >> You are correct, this is actually misstating the problem. It is not the >> security credentials that need to be a single set. Any SDP level >> security configuration used on individual media description MUST be >> possible to use when creating a bundle group across the full or a >> sub-set of the media description offered as a bundle group. >> >> This works fine for the below listed ones by following the limiations >> indicated in SDP MUX attributes, i.e. transport or identical. But for a >> future mechanism that is defined with bundle in mind from the start >> could have individual configurations. >> >>> >>> >>> When using SRTP this will be the >>> case, at least for the IETF defined key-management solutions >>> due to >>> their SDP attributes (a=crypto, a=fingerprint, a=mikey) and their >>> classification in [I-D.ietf-mmusic-sdp-mux-attributes]. >>> >> >> I will have to think on how to re-write this. >> >> Cheers >> >> Magnus Westerlund >> >> ---------------------------------------------------------------------- >> Media Technologies, Ericsson Research >> ---------------------------------------------------------------------- >> Ericsson AB | Phone +46 10 7148287 >> Färögatan 6 | Mobile +46 73 0949079 >> SE-164 80 Stockholm, Sweden | mailto: [email protected] >> ---------------------------------------------------------------------- >> >> _______________________________________________ >> rtcweb mailing list >> [email protected] >> https://www.ietf.org/mailman/listinfo/rtcweb > > -- Magnus Westerlund ---------------------------------------------------------------------- Media Technologies, Ericsson Research ---------------------------------------------------------------------- Ericsson AB | Phone +46 10 7148287 Färögatan 6 | Mobile +46 73 0949079 SE-164 80 Stockholm, Sweden | mailto: [email protected] ---------------------------------------------------------------------- _______________________________________________ mmusic mailing list [email protected] https://www.ietf.org/mailman/listinfo/mmusic