[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: DTLS-SRTP harming GETS [was RE: Additional use cases? (Re: Plan for moving forward)]




Francois,

We don't make decisions at a meeting in the IETF.

We definitely didn't say that DTLS-SRTP cannot be changed. If you recall, change control was a big part of the arguments at the meeting.

I am not (cannot) stopping anyone from making progress. I am simply presenting a use case and seeking clarification on why some properties are more important than others. In some systems, optimization of computational and communication overhead is important. If we have to sacrifice some security properties, as long as the risks are well understood, it should be allowed (that's one of the reasons we have the security considerations section).

The necessary question to ask is what security properties are considered crucial to all use cases and why. That is an important discussion to have. One of the lessons from history is that IKE main mode had some properties people didn't care for, that made the quick mode popular and subsequently in IKEv2 we got rid of some of those properties in the interest of fewer RTs. Now of course, IKEv2 effort was motivated by a lot of other reasons too.

regards,
Lakshminath

On 6/13/2007 8:57 AM, Francois Audet wrote:
The only argument against that I see so far is that
DTLS-SRTP is the
chosen protocol and the chosen protocol must not be changed.

Didn't we agree on this at the last meeting?

Isn't it time to move on?