Re: draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?

Eric Rescorla <[email protected]>
Newsgroups gmane.ietf.mmusic
Message-ID <CABcZeBN000+Qm=FJpB_6bp8WYQhQ7E84XVYO4bXyby2U-DcWew@mail.gmail.com>
On Fri, May 26, 2017 at 3:30 PM, Christer Holmberg <
[email protected]> wrote:

>
> Hi,
>
> I have updated the PR. The text now says that the offer must not
> *finalise* the DTLS handshake until it has received the answer.
>

What does that mean? Finalize isn't a DTLS concept.

Also, you say that if you initiate the handshake before the answer
is received you are vulnerable to attacks. What attacks are those?

-Ekr


>
> The text still allows to process media that is received before the answer
> is received. I know Martin doesn¹t like that, and I have no idea what the
> sec people will think about it, but I am trying to find some common
> ground. I want to move the draft forward.
>
> Is this something everyone can live with?
>
> Š
>
>
> >> Also, if I understand the FEDEX use-case, not only would you have to be
> >> able to receive media - if you are e.g., going to provide DTMFs you
> >>could
> >> also have to SEND data? Or?
> >
> >Yeah, sending DTMF to who-knows isn't a good idea.  I'm not clear on
> >whether sending DTMF is part of the arrangement.  Sounds like a great
> >way to avoid tarriffs altogether; I'm surprised that service providers
> >would even allow that.
>
> Actually, before you get the SDP answer you can¹t send any DTMFsŠ
>
> Regards,
>
> Christer
>
> _______________________________________________
> mmusic mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/mmusic
>

_______________________________________________
mmusic mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mmusic
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.