Re: Draft new version: draft-ietf-simple-msrp-cema-06

Ben Campbell <[email protected]> Wed, 27 Jun 2012 15:40:13 -0500
Newsgroups gmane.ietf.simple
Message-ID <[email protected]>
As individual:

This revision, along with discussion, addresses my comments to my satisfaction.

I have no objection to the proposed new normative change. When I first thought about this addition, I wondered why we would burden CEMA with it, rather than find a way to apply it to MSRP in general. But on reflection, it seems like CEMA is really about making MSRP easier to use over middleboxes. I think this makes it reasonable to hold CEMA to a higher standard for fingerprint management. If we do some general update to MSRP in the future, we might still consider adding the requirement to the general case.

We should consider, however,  whether CEMA has any common use cases where a self-signed certificate and associated fingerprint would change all the time. (e.g. if self-signed certs were ephemeral).

Thanks!

Ben.



On Jun 27, 2012, at 3:33 PM, Ben Campbell wrote:

> As Chair:
> 
> Hi Everyone:
> 
> Christer, thanks for submitting this.
> 
> Everyone,  please take a quick look at the security considerations in this version, and send comments ASAP if you see an issue. If you made comments in the WGLC, please confirm whether your comments are addressed (I'm not sure if anyone but me did--maybe Paul?). If we don't see an objection the end of the week, we plan to restart the process to progress this.
> 
> Additionally, we've had a Security AD suggestion to add text (probably to section 7.7)  to the effect of the following, which would add SHOULD level normative requirements to watch for changes in a fingerprint for an identity, and warn of any changes. If anyone objects to adding that, please speak up ASAP.
> 
>> "When a UA receives a fingerprint, that represents a binding
>> between the identity as established by TLS and that established
>> via SDP. As previously noted, the fingerprint is vulnerable to
>> an active MITM attack from any on-path proxy. UAs SHOULD
>> therefore locally store fingerprints associated with the
>> relevant identities when first seen, and SHOULD warn when a
>> new fingerprint is seen for what otherwise appears to be the
>> same peer identity. While there are valid reasons for keys
>> to change from time to time, that ought be the exception,
>> hence the suggested warning."
> 
> 
> 
> Thanks!
> 
> Ben.
> 
> 
> 
> 
> On Jun 25, 2012, at 6:07 PM, Christer Holmberg wrote:
> 
>> Hi,
>> 
>> Based on Ben's comments, I've submitted a new version (-06) of the cema draft, with some modifications in the security considerations section. The new text should address Ben's issues and suggestions.
>> 
>> Regards,
>> 
>> Christer
>> _______________________________________________
>> Simple mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/simple
>