Re: [rtcweb] BUNDLE: Attempting to resolve security consideration

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.mmusic
Message-ID <CABcZeBPiexFiho7A5pVDt4zu9n3K1sY9+HMCcqUd+FBgF8Hb=g@mail.gmail.com>
On Sun, Mar 26, 2017 at 1:41 PM, Magnus Westerlund <
[email protected]> wrote:

> Hi,
>
> I have attempted to address the issue discussed below by reformulating
> that paragraph to read:
>
>    When the BUNDLE extension is used, the set of configurations of the
>    security mechanism used in all the bundled media descriptions will
>    need to be compatible for simultaneously use, at least per direction
>    or endpoint.


I'm not sure I understand what "compatible for simultaneously use" means.

-Ekr

When using SRTP this will be the case, at least for the
>    IETF defined key-management solutions due to their SDP attributes
>    (a=crypto, a=fingerprint, a=mikey) and their classification in
>    [I-D.ietf-mmusic-sdp-mux-attributes].
>
>
> So, does this work?
>
> Cheers
>
> Magnus
>
>
>
> Den 2017-03-14 kl. 03:47, skrev Magnus Westerlund:
>
>> Den 2017-03-10 kl. 16:31, skrev Eric Rescorla:
>>
>>>
>>>        When the BUNDLE extension is used, a single set of security
>>>        credentials over the bundled media descriptions will need to be
>>> used,
>>>        at least per direction or endpoint.
>>>
>>>
>>> Actually, why does this have to be the case? I mean, we require it, but
>>> if you have the MID extension, you could easily not do this.
>>>
>>>
>> You are correct, this is actually misstating the problem. It is not the
>> security credentials that need to be a single set. Any SDP level
>> security configuration used on individual media description MUST be
>> possible to use when creating a bundle group across the full or a
>> sub-set of the media description offered as a bundle group.
>>
>> This works fine for the below listed ones by following the limiations
>> indicated in SDP MUX attributes, i.e. transport or identical. But for a
>> future mechanism that is defined with bundle in mind from the start
>> could have individual configurations.
>>
>>
>>>
>>>     When using SRTP this will be the
>>>        case, at least for the IETF defined key-management solutions
>>> due to
>>>        their SDP attributes (a=crypto, a=fingerprint, a=mikey) and their
>>>        classification in [I-D.ietf-mmusic-sdp-mux-attributes].
>>>
>>>
>> I will have to think on how to re-write this.
>>
>> Cheers
>>
>> Magnus Westerlund
>>
>> ----------------------------------------------------------------------
>> Media Technologies, Ericsson Research
>> ----------------------------------------------------------------------
>> Ericsson AB                 | Phone  +46 10 7148287
>> Färögatan 6                 | Mobile +46 73 0949079
>> SE-164 80 Stockholm, Sweden | mailto: [email protected]
>> ----------------------------------------------------------------------
>>
>> _______________________________________________
>> rtcweb mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/rtcweb
>>
>
>
> --
>
> Magnus Westerlund
>
> ----------------------------------------------------------------------
> Media Technologies, Ericsson Research
> ----------------------------------------------------------------------
> Ericsson AB                 | Phone  +46 10 7148287
> Färögatan 6                 | Mobile +46 73 0949079
> SE-164 80 Stockholm, Sweden | mailto: [email protected]
> ----------------------------------------------------------------------
>
>

_______________________________________________
mmusic mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mmusic
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.