Tuesday, July 28, 2009

Re: [Geopriv] Identity and IP address considerations

Well, first of all the draft has no discussion of the issues, even the
references to HELD and l7-lcp-ps (for this subject). Then, I think the
issues for 3rd party use of IP as an identifier is different somewhat
from first party use. Among other things, for example, a device can
often bypass a VPN, whereas the 3rd party can't.

Brian

> -----Original Message-----
> From: Richard Barnes [mailto:rbarnes@bbn.com]
> Sent: Tuesday, July 28, 2009 5:07 AM
> To: Rosen, Brian
> Cc: geopriv@ietf.org
> Subject: Re: [Geopriv] Identity and IP address considerations
>
> It seems like the risks of IP addresses as identifiers are pretty
> well-trodden territory. How would your notional text differ from
> what's
> already in l7-lcp-ps and HELD?
> --Richard
>
> Rosen, Brian wrote:
> > In the HELD Identity draft, one of the uses is a 3rd party OBO
> request
> > for location. An example use case is interim deployment of VoIP
> > emergency calls, before the device is upgraded to query a LIS via an
> LCP
> > itself. It will be common to use an IP address in this case.
> >
> > The draft does not discuss the cautions we have long discussed when
> > using an IP address as an identifier. It's quite clear that an IP
> > address WILL be used for this case, and denying it is silly.
> > Considerations for its use should be provided. I think we want text
> > that discusses issues such as the effect of NAT and VPNs, perhaps a
> > discussion of needing return routability testing to assure the 3rd
> party
> > that it has a good IP address, etc.
> >
> > Some of the latter considerations may also apply to other forms of
> > identity that may be used with this draft.
> >
> > Brian
> > _______________________________________________
> > Geopriv mailing list
> > Geopriv@ietf.org
> > https://www.ietf.org/mailman/listinfo/geopriv
> >
_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv