Fwd: draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?

Ben Campbell <[email protected]>
Newsgroups gmane.ietf.mmusic
Message-ID <[email protected]>
Can people live with the PR as it currently stands, even if it’s not “perfect”? If not, what would it take to be able to live with it? It’s been almost 2 months since the IETF LC completed. It would be nice to progress this soon.

Thanks!

Ben.

> Begin forwarded message:
> 
> From: Christer Holmberg <[email protected]>
> Subject: Re: [MMUSIC] draft-dtls-sdp: Allow offerer to establish DTLS association before it has received the SDP answer?
> Date: May 29, 2017 at 5:41:19 AM CDT
> To: Martin Thomson <[email protected]>, Eric Rescorla <[email protected]>
> Cc: "[email protected]" <[email protected]>
> 
> Hi,
> 
> I have updated the PR.
> 
> The text now says ³complete² instead of ³finalise². In addition, I removed
> the text about attacks, and only kept the text saying that media received
> before the answer must be considered unauthenticated.
> 
> If people are still not happy with the text, I¹d really appreciate some
> text.
> 
> Regards,
> 
> Christer
> 
> 
> 
> On 26/05/17 14:32, "mmusic on behalf of Christer Holmberg"
> <[email protected] on behalf of [email protected]>
> wrote:
> 
>> Hi,
>> 
>> You are the DTLS gurus - please suggest changes that makes the text
>> correct - and still hopefully keeps Cullen happy :)
>> 
>> Regards,
>> 
>> Christer
>> 
>> 
>> On 26/05/17 14:01, "Martin Thomson" <[email protected]> wrote:
>> 
>>> On 26 May 2017 at 20:37, Eric Rescorla <[email protected]> wrote:
>>>> Also, you say that if you initiate the handshake before the answer
>>>> is received you are vulnerable to attacks. What attacks are those?
>>> 
>>> It should be "complete" - on the assumption that a completed handshake
>>> leads immediately to using the connection.  Really, it's using the
>>> connection (sending or receiving data or using exporters) that puts
>>> you at risk, but I don't think that it's worth putting that fine a
>>> distinction on it.
>> 
>> _______________________________________________
>> mmusic mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/mmusic
> 
> _______________________________________________
> mmusic mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/mmusic

_______________________________________________
mmusic mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mmusic
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.