Re: DTLS over DCCP and SRTP-DTLS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Tom,

Thanks for looking into this - I'm glad to see there are no issues. I've cc'd the authors of the DTLS-SRTP draft, in case they wish to add a paragraph on transport issues, noting that DTLS-SRTP should work over UDP and DCCP alike.

Cheers,
Colin



On 16 Oct 2007, at 18:41, Phelan, Tom wrote:
In Chicago, Colin suggested that I look at an ongoing item in the AVT WG
that was specifying the use of SRTP with DTLS
(draft-ietf-avt-dtls-srtp-00.txt), and see if there were any necessary
adjustments that DTLS over DCCP needed to make.

Well, I've looked at it and there doesn't seem to be any need to adjust
DTLS over DCCP to accommodate SRTP-DTLS.  SRTP-DTLS specifies some
extensions to the DTLS handshake, but those extensions are transparent
to the way encapsulation is done for DTLS over DCCP. It also specifies
that flows using SRTP-DTLS switch to SRTP encapsulation after the DTLS
handshake and exchange of keying info (including new keys for the SRTP
operation).  This is also transparent to DTLS over DCCP.

Also, I think that DTLS over DCCP is transparent to SRTP-DTLS.  The
SRTP-DTLS draft makes no explicit mention of underlying transport
protocol and it seems to me that the methods specified work with either UDP or DCCP transport. The authors of SRTP-DTLS might consider adding a
short informative section on transport protocol issues, but I don't
think that's strictly necessary.

At any rate, I believe this closes all issues related to DTLS over DCCP (assuming that everyone agrees with my assessment, of course :-)). I'll be sending a new version of the DTLS over DCCP draft with minor editing
changes momentarily, and hopefully we can proceed to WG last call on
that (chair hat off at the moment :-)).

Tom P.



[Index of Archives]     [Linux Kernel Development]     [Linux DCCP]     [IETF Annouce]     [Linux Networking]     [Git]     [Security]     [Linux Assembly]     [Bugtraq]     [Yosemite]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux SCSI]     [DDR & Rambus]

  Powered by Linux