[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Speechsc] RAI review of draft-ietf-speechsc-mrcpv2-19
Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft
Roni
> -----Original Message-----
> From: Eric Burger [mailto:eburger at standardstrack.com]
> Sent: Thursday, July 09, 2009 11:28 PM
> To: Roni Even
> Cc: Saravanan Shanmugham; Daniel Burnett; speechsc at ietf.org;
> rai at ietf.org
> Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19
>
> The reality is that NO ONE has implemented any security to date. The
> GENART reviewer raised the same issue, and so far the work group has
> the same response: MRCPv2 (the speechsc work group) is not planning on
> figuring out which of the seven key exchange mechanisms to use in
> SIP. We are counting on the community publishing something, and
> people using it. After all, we are the "using SIP for media resource
> control" work group, not the "media resource control work group using
> something like SIP for control."
>
> Does this work for you?
>
> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>
> > [snip]
> >
> >
> > 18. In section 12.3 the suggestion is to use SRTP as the mandatory
> > interoperability mode. If the reason for mandating SRTP is for a
> > common mode you should also decide on a key exchange mechanism. I
> > suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-
> not-mandatory-02
> > for discussion on media security.