
From Even.roni@huawei.com  Tue Jul  7 12:41:58 2009
Return-Path: <Even.roni@huawei.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id ED81E28C2FF; Tue,  7 Jul 2009 12:41:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.629
X-Spam-Level: 
X-Spam-Status: No, score=-0.629 tagged_above=-999 required=5 tests=[AWL=-0.135, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, HTML_MESSAGE=0.001, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Vlm+lyPnAvA1; Tue,  7 Jul 2009 12:41:49 -0700 (PDT)
Received: from szxga03-in.huawei.com (unknown [119.145.14.66]) by core3.amsl.com (Postfix) with ESMTP id 5737E28C540; Tue,  7 Jul 2009 12:41:49 -0700 (PDT)
Received: from huawei.com (szxga03-in [172.24.2.9]) by szxga03-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KMF009XMG07HT@szxga03-in.huawei.com>; Wed, 08 Jul 2009 03:40:55 +0800 (CST)
Received: from huawei.com ([172.24.1.3]) by szxga03-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KMF004LPG07XI@szxga03-in.huawei.com>; Wed, 08 Jul 2009 03:40:55 +0800 (CST)
Received: from windows8d787f9 (bzq-82-81-156-32.red.bezeqint.net [82.81.156.32]) by szxml01-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug  8 2006)) with ESMTPA id <0KMF001JOFZNP9@szxml01-in.huawei.com>; Wed, 08 Jul 2009 03:40:55 +0800 (CST)
Date: Tue, 07 Jul 2009 22:40:17 +0300
From: Roni Even <Even.roni@huawei.com>
To: sarvi@cisco.com, dburnett@voxeo.com
Message-id: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
MIME-version: 1.0
X-Mailer: Microsoft Office Outlook 12.0
Content-type: multipart/alternative; boundary="Boundary_(ID_tDM6/tBc+CJPdmIwZyVDuw)"
Content-language: en-us
Thread-index: Acn/OlCXdRdlr834SLWofXw8dvS9rQ==
X-Mailman-Approved-At: Wed, 08 Jul 2009 09:26:14 -0700
Cc: speechsc@ietf.org, oran@cisco.com, rai@ietf.org
Subject: [Speechsc] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Jul 2009 19:41:58 -0000

This is a multi-part message in MIME format.

--Boundary_(ID_tDM6/tBc+CJPdmIwZyVDuw)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT

Hi,

I was assigned to do a RAI review of the draft.  The draft looks ready for
publication to me. I have some comments mostly editorial. 

The only issue I see that is not pure editorial is the issue of the
different parameters like confidence threshold, sensitivity level (see
comments 11, 13, 15, 16 and 17). I think that some clarification on the
semantics and the scale (for example are the values linearly spaced) as well
as when they are useful will be helpful to implementers.

1.       In figure 1 Expand the abbreviations TTS, ASR, SV , SI and how they
are related to the media resource types in 3.1

2.       In figure 1 there is a SIP dialog between the MRCPv2 client and the
media source/sink, what is this dialog, I only saw in section 4 a dialog
between the client and server.

3.       In section 3.2 you have "For example:  <sip:mrcpv2@example.net>
sip:mrcpv2@example.net" twice one after the other.

 

4.       In the example in section 4.2 you "a=cmid:1", cmid is specified
later in the document so maybe you can add some reference to where it is
specified

 

5.       In the example is section 4.2 and in following examples you have
"m=audio 49170 RTP/AVP 0 96" but do not have an rtpmap parameter for mapping
96 (dynamic payload type number) to a media encoding name.

 

6.       In section 4.3 "Also note that more that one media session can be
associated with a single resource if need be, but this scenario is not
useful for the current set of resources". There is a typo the second "that"
should be "than". I am also not sure if the current syntax in this document
can support the mode.

 

 

7.       In section 4.3 "The formatting of the"cmid" attribute in SDP
RFC3388 [RFC4566]". I think you meant SDP grouping and need the reference to
RFC 3388.

 

 

8.       In section 5.1 "The message-length field specifies the length of
the message, including the start-line" is the length in Bytes, there is no
unit specified.

 

9.       In section 6.3.1, typo you have "Verfication " instead of
verification. It appears twice in the section.

 

10.   In the example in section 7 you have "m=audio 0 RTP/AVP 0 1 3" payload
type 1 was deleted from the IANA registry, maybe have another payload type
number.

 

11.   In section 9.4.1, 9.4.2 and 9.4.3 you specify confidence threshold,
sensitivity level and speed vs accuracy. What is the scale here; is it
linear between 0 and 1. What is the absolute value of the number, if you
receive the same confidence level from two recognizers are they the same
(e.g. when using context block to switch servers).  For the speed vs
accuracy, how does the client know what is the relation between the value
and the number of available sessions, since this seems to be the reason for
using this parameter.

 

12.   In 9.4.9 and in 10.4.8, 11.4.11 what are the values for
media-type-value, you also mention audio and video but it looks to me that
this document only discusses voice.

 

13.   In 9.4.35 and 9.4.36 what is the scale for the consistency here. How
does one know what close means. What is the consistency between different
recognizers.

 

14.   In section 9.6.3.3 in the example (figure 2) confidence should be 0.75
and not 75

 

15.   In section 10.4.1 it is not clear how you measure the sensitivity in
order to specify, is it based on some SNR translated to 0 to 1 scale?

 

16.   In 11.4.6 the same issue with the scale, how does the client know how
to set a value when working with different speaker verification servers.

 

17.   In 11.5.2.9 you state that the verification-score is not a
probability, so what is it. How can the client decide if, for example, 0 is
a good score for specifying the threshold.  I also noticed that the values
in the example in section 11.5.2.10 are very precise like 0.98514 is this
the expected precision. The examples here and in section 11.11 do not show
the threshold, if the threshold is required for this flow why not show it in
the example?

 

18.   In section 12.3 the suggestion is to use SRTP as the mandatory
interoperability mode. If the reason for mandating SRTP is for a common mode
you should also decide on a key exchange mechanism. I suggest you look at
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02 for
discussion on media security.

 

19.   In section13.7.2 you specify the attribute resource as session level
yet in the example in section 4.2 it is a media level attribute. The same
goes for the channel attribute

 

Thanks

 

Roni Even

 

 


--Boundary_(ID_tDM6/tBc+CJPdmIwZyVDuw)
Content-type: text/html; charset=us-ascii
Content-transfer-encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:x=3D"urn:schemas-microsoft-com:office:excel" =
xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint" =
xmlns:a=3D"urn:schemas-microsoft-com:office:access" =
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" =
xmlns:s=3D"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" =
xmlns:rs=3D"urn:schemas-microsoft-com:rowset" xmlns:z=3D"#RowsetSchema" =
xmlns:b=3D"urn:schemas-microsoft-com:office:publisher" =
xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadsheet" =
xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" =
xmlns:odc=3D"urn:schemas-microsoft-com:office:odc" =
xmlns:oa=3D"urn:schemas-microsoft-com:office:activation" =
xmlns:html=3D"http://www.w3.org/TR/REC-html40" =
xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/" =
xmlns:rtc=3D"http://microsoft.com/officenet/conferencing" =
xmlns:D=3D"DAV:" xmlns:Repl=3D"http://schemas.microsoft.com/repl/" =
xmlns:mt=3D"http://schemas.microsoft.com/sharepoint/soap/meetings/" =
xmlns:x2=3D"http://schemas.microsoft.com/office/excel/2003/xml" =
xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd" =
xmlns:ois=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" =
xmlns:dir=3D"http://schemas.microsoft.com/sharepoint/soap/directory/" =
xmlns:ds=3D"http://www.w3.org/2000/09/xmldsig#" =
xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint/dsp" =
xmlns:udc=3D"http://schemas.microsoft.com/data/udc" =
xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema" =
xmlns:sub=3D"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/"=
 xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#" =
xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" =
xmlns:sps=3D"http://schemas.microsoft.com/sharepoint/soap/" =
xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance" =
xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/soap" =
xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile" =
xmlns:udcp2p=3D"http://schemas.microsoft.com/data/udc/parttopart" =
xmlns:wf=3D"http://schemas.microsoft.com/sharepoint/soap/workflow/" =
xmlns:dsss=3D"http://schemas.microsoft.com/office/2006/digsig-setup" =
xmlns:dssi=3D"http://schemas.microsoft.com/office/2006/digsig" =
xmlns:mdssi=3D"http://schemas.openxmlformats.org/package/2006/digital-sig=
nature" =
xmlns:mver=3D"http://schemas.openxmlformats.org/markup-compatibility/2006=
" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns:mrels=3D"http://schemas.openxmlformats.org/package/2006/relationshi=
ps" xmlns:spwp=3D"http://microsoft.com/sharepoint/webpartpages" =
xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/types"=
 =
xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/messag=
es" =
xmlns:pptsl=3D"http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/=
" =
xmlns:spsl=3D"http://microsoft.com/webservices/SharePointPortalServer/Pub=
lishedLinksService" xmlns:Z=3D"urn:schemas-microsoft-com:" =
xmlns:st=3D"&#1;" xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p.MsoCommentText, li.MsoCommentText, div.MsoCommentText
	{mso-style-priority:99;
	mso-style-link:"Comment Text Char";
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:0in;
	line-height:115%;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-priority:99;
	mso-style-link:"Plain Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.5pt;
	font-family:Consolas;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.CommentTextChar
	{mso-style-name:"Comment Text Char";
	mso-style-priority:99;
	mso-style-link:"Comment Text";
	font-family:"Calibri","sans-serif";}
span.PlainTextChar
	{mso-style-name:"Plain Text Char";
	mso-style-priority:99;
	mso-style-link:"Plain Text";
	font-family:Consolas;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:1532768528;
	mso-list-type:hybrid;
	mso-list-template-ids:-203629182 67698703 67698713 67698715 67698703 =
67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level4
	{mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level7
	{mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoCommentText><span =
style=3D'font-size:11.0pt;line-height:115%'>Hi,<o:p></o:p></span></p>

<p class=3DMsoCommentText><span =
style=3D'font-size:11.0pt;line-height:115%'>I was
assigned to do a RAI review of the draft. &nbsp;The draft looks ready =
for
publication to me. I have some comments mostly editorial. =
<o:p></o:p></span></p>

<p class=3DMsoCommentText><span =
style=3D'font-size:11.0pt;line-height:115%'>The
only issue I see that is not pure editorial is the issue of the =
different
parameters like confidence threshold, sensitivity level (see comments =
11, 13,
15, 16 and 17). I think that some clarification on the semantics and the =
scale
(for example are the values linearly spaced) as well as when they are =
useful
will be helpful to implementers.<o:p></o:p></span></p>

<p class=3DMsoCommentText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:
l0 level1 lfo1'><![if !supportLists]><span =
style=3D'font-size:11.0pt;line-height:
115%'><span style=3D'mso-list:Ignore'>1.<span style=3D'font:7.0pt "Times =
New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;line-height:115%'>In figure 1 Expand the abbreviations TTS, ASR, =
SV , SI
and how they are related to the media resource types in =
3.1<o:p></o:p></span></p>

<p class=3DMsoCommentText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:
l0 level1 lfo1'><![if !supportLists]><span =
style=3D'font-size:11.0pt;line-height:
115%'><span style=3D'mso-list:Ignore'>2.<span style=3D'font:7.0pt "Times =
New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;line-height:115%'>In figure 1 there is a SIP dialog between the =
MRCPv2
client and the media source/sink, what is this dialog, I only saw in =
section 4
a dialog between the client and server.<o:p></o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>3.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 3.2 you have =
&#8220;For
example: <a href=3D"sip:mrcpv2@example.net"><span =
style=3D'color:windowtext;
text-decoration:none'>sip:mrcpv2@example.net</span></a>&#8221; twice one =
after
the other.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>4.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In the example in section 4.2 =
you
&#8220;a=3Dcmid:1&#8221;, cmid is specified later in the document so =
maybe you
can add some reference to where it is specified<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>5.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In the example is section 4.2 =
and in
following examples you have &#8220;m=3Daudio 49170 RTP/AVP 0 96&#8221; =
but do not
have an rtpmap parameter for mapping 96 (dynamic payload type number) to =
a
media encoding name.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>6.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 4.3 &#8220;Also =
note that
more that one media session can be associated with a single resource if =
need
be, but this scenario is not useful for the current set of =
resources&#8221;.
There is a typo the second &#8220;that&#8221; should be =
&#8220;than&#8221;. I
am also not sure if the current syntax in this document can support the =
mode.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>7.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 4.3 &#8220;The =
formatting
of the&quot;cmid&quot; attribute in SDP RFC3388 [RFC4566]&#8221;. I =
think you
meant SDP grouping and need the reference to RFC =
3388.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>8.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 5.1 =
&#8220;</span><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>The =
message-length
field specifies the length of the message, including the =
start-line&#8221; is
the length in Bytes, there is no unit specified.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>9.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 6.3.1, typo you =
have
&#8220;Verfication &#8220; instead of verification. It appears twice in =
the
section.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>10.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In the example in section 7 =
you have
&#8220;m=3Daudio 0 RTP/AVP 0 1 3&#8221; payload type 1 was deleted from =
the IANA
registry, maybe have another payload type number.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>11.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 9.4.1, 9.4.2 and =
9.4.3
you specify confidence threshold, sensitivity level and speed vs =
accuracy. What
is the scale here; is it linear between 0 and 1. What is the absolute =
value of
the number, if you receive the same confidence level from two =
recognizers are
they the same (e.g. when using context block to switch servers).&nbsp; =
For the
speed vs accuracy, how does the client know what is the relation between =
the
value and the number of available sessions, since this seems to be the =
reason
for using this parameter.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>12.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In 9.4.9 and in 10.4.8, =
11.4.11 what
are the values for media-type-value, you also mention audio and video =
but it
looks to me that this document only discusses =
voice.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>13.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In 9.4.35 and 9.4.36 what is =
the
scale for the consistency here. How does one know what close means. What =
is the
consistency between different recognizers.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>14.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 9.6.3.3 in the =
example
(figure 2) confidence should be 0.75 and not 75<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>15.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 10.4.1 it is not =
clear
how you measure the sensitivity in order to specify, is it based on some =
SNR
translated to 0 to 1 scale?<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>16.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In 11.4.6 the same issue with =
the
scale, how does the client know how to set a value when working with =
different
speaker verification servers.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>17.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In 11.5.2.9 you state that =
the
verification-score is not a probability, so what is it. How can the =
client decide
if, for example, 0 is a good score for specifying the threshold.&nbsp; I =
also
noticed that the values in the example in section 11.5.2.10 are very =
precise
like 0.98514 is this the expected precision. The examples here and in =
section
11.11 do not show the threshold, if the threshold is required for this =
flow why
not show it in the example?<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>18.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section 12.3 the =
suggestion is to
use SRTP as the mandatory interoperability mode. If the reason for =
mandating
SRTP is for a common mode you should also decide on a key exchange =
mechanism. I
suggest you look at <a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02">=
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02</a>
for discussion on media security.<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo1'><![if !supportLists]><span
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><span
style=3D'mso-list:Ignore'>19.<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;
</span></span></span><![endif]><span dir=3DLTR></span><span =
style=3D'font-size:
11.0pt;font-family:"Calibri","sans-serif"'>In section13.7.2 you specify =
the attribute
resource as session level yet in the example in section 4.2 it is a =
media level
attribute. The same goes for the channel attribute<o:p></o:p></span></p>

<p class=3DMsoListParagraph><o:p>&nbsp;</o:p></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Thanks<o:p>=
</o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Roni
Even<o:p></o:p></span></p>

<p class=3DMsoPlainText><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p>&nbsp;=
</o:p></span></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</body>

</html>

--Boundary_(ID_tDM6/tBc+CJPdmIwZyVDuw)--

From Christian.Groves@nteczone.com  Wed Jul  8 17:37:28 2009
Return-Path: <Christian.Groves@nteczone.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0E96A3A6879 for <speechsc@core3.amsl.com>; Wed,  8 Jul 2009 17:37:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.345
X-Spam-Level: 
X-Spam-Status: No, score=-2.345 tagged_above=-999 required=5 tests=[AWL=0.260,  BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, RELAY_IS_203=0.994]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id h0v04okBksUd for <speechsc@core3.amsl.com>; Wed,  8 Jul 2009 17:37:26 -0700 (PDT)
Received: from ipmail01.adl6.internode.on.net (ipmail01.adl6.internode.on.net [203.16.214.146]) by core3.amsl.com (Postfix) with ESMTP id 19E0F3A69B8 for <speechsc@ietf.org>; Wed,  8 Jul 2009 17:37:25 -0700 (PDT)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: Al4BAIvYVEp20Oe3/2dsb2JhbAAI0SeECAWBOg
X-IronPort-AV: E=Sophos;i="4.42,371,1243780200"; d="scan'208";a="390647708"
Received: from ppp118-208-231-183.lns10.mel6.internode.on.net (HELO [127.0.0.1]) ([118.208.231.183]) by ipmail01.adl6.internode.on.net with ESMTP; 09 Jul 2009 10:07:50 +0930
Message-ID: <4A553BD5.80106@nteczone.com>
Date: Thu, 09 Jul 2009 10:37:41 +1000
From: Christian Groves <Christian.Groves@nteczone.com>
User-Agent: Thunderbird 2.0.0.22 (Windows/20090605)
MIME-Version: 1.0
To: speechsc@ietf.org
References: <4A2F20D4.3000409@nteczone.com>
In-Reply-To: <4A2F20D4.3000409@nteczone.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Cc: Even.roni@huawei.com
Subject: Re: [Speechsc] Question about Verification
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Jul 2009 00:37:28 -0000

Hello,

Can anyone explain the apparent contradiction between the text and the 
syntax below?

Regards, Christian

Christian Groves wrote:
> Hello,
>
> I've been reviewing the verification section of 
> draft-ietf-speechsc-mrcpv2-19 there appears to be some contradiction 
> between the text and the syntax. i.e.
>
> Section 11.5.2.3.  "Incremental" states:
>
>   The first "<voiceprint>" element MAY contain an "<incremental>"
>   element with the incremental scores of how well the last utterance
>   matched the voiceprint.
>
> However section 16.3.  "Verification Results Schema Definition" states:
> *  */*   <define name="restVoiceprintContent">*
>       <attribute name="id">
>         <data type="string"/>
>       </attribute>
>       <interleave>
>         <optional>
> *           <element name="incremental">                    <------- ???*
>             <ref name="restCommonContent"/>
>           </element>
>         </optional>
>        .../
>
> I don't know if I'm reading this correctly but to me section 11.5.2.3 
> doesn't say anything about incremental being used in subsequent 
> voices. So I would assume that it would not be part of the 
> restVoicePrintContent schema?
>
> Another example:
>
> Section 11.5.2.5.  "Utterance-Length"
>
>   This element MAY occur within either the "<incremental>" or
>   "<cumulative>" elements within the first "<voiceprint>" element.
> However section 16.3 states:
>  / *<define name="restCommonContent">  <----------------- ???*
>       <interleave>
>         <optional>
>           <element name="decision">
>             <ref name="decisionContent"/>
>           </element>
>         </optional>
>         <optional>
> *          <element name="utterance-length">   <-----------???*
>             <ref name="utterance-lengthContent"/>
>           </element>
>         </optional>/
>
> Again I don't know if I'm reading this correctly but the text for 
> utterance says its applicable for the first voiceprint but the schema 
> shows it only relevant for subsequent voiceprints???
>
> Another example is:
> Section 11.5.2.8.  "Adapted" which states:
>
>   This element is found within the "<voiceprint>" element within the
>   verification results.
>
> However 16.3 states:
> /*<define name="firstVoiceprintContent">*
>       <attribute name="id">
>         <data type="string"/>
>       </attribute>
>       <interleave>
>         <optional>
> *          <element name="adapted">*
>             <data type="boolean"/>
>           </element>/
> Again I'm confused as previous text says that certain elements are 
> applicable to the first voiceprint but the text does not state this 
> for the adapted element yet the schema shows it only belongs to the 
> first Voiceprint.
>
> Can anyone shed some slight on this?
>
> Regards, Christian
> _______________________________________________
> Speechsc mailing list
> Speechsc@ietf.org
> https://www.ietf.org/mailman/listinfo/speechsc
> Supplemental web site:
> &lt;http://www.standardstrack.com/ietf/speechsc&gt;
>

From eburger@standardstrack.com  Thu Jul  9 13:27:42 2009
Return-Path: <eburger@standardstrack.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id B99EA28C274; Thu,  9 Jul 2009 13:27:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.52
X-Spam-Level: 
X-Spam-Status: No, score=-2.52 tagged_above=-999 required=5 tests=[AWL=0.079,  BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rs+bFDJ7LUBa; Thu,  9 Jul 2009 13:27:41 -0700 (PDT)
Received: from gs19.inmotionhosting.com (gs19.inmotionhosting.com [205.134.252.251]) by core3.amsl.com (Postfix) with ESMTP id A06E828C14F; Thu,  9 Jul 2009 13:27:41 -0700 (PDT)
Received: from neustargw.va.neustar.com ([209.173.53.233] helo=[10.31.32.174]) by gs19.inmotionhosting.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69) (envelope-from <eburger@standardstrack.com>) id 1MP0Dm-0007xt-V2; Thu, 09 Jul 2009 13:27:59 -0700
Message-Id: <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
From: Eric Burger <eburger@standardstrack.com>
To: Roni Even <Even.roni@huawei.com>
In-Reply-To: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
Content-Type: multipart/signed; boundary=Apple-Mail-7-428628199; micalg=sha1; protocol="application/pkcs7-signature"
Mime-Version: 1.0 (Apple Message framework v935.3)
Date: Thu, 9 Jul 2009 16:28:04 -0400
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
X-Mailer: Apple Mail (2.935.3)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gs19.inmotionhosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - standardstrack.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
Cc: speechsc@ietf.org, Saravanan Shanmugham <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Jul 2009 20:27:42 -0000

--Apple-Mail-7-428628199
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

The reality is that NO ONE has implemented any security to date. The  
GENART reviewer raised the same issue, and so far the work group has  
the same response: MRCPv2 (the speechsc work group) is not planning on  
figuring out which of the seven key exchange mechanisms to use in  
SIP.  We are counting on the community publishing something, and  
people using it.  After all, we are the "using SIP for media resource  
control" work group, not the "media resource control work group using  
something like SIP for control."

Does this work for you?

On Jul 7, 2009, at 3:40 PM, Roni Even wrote:

> [snip]
>
>
> 18.   In section 12.3 the suggestion is to use SRTP as the mandatory  
> interoperability mode. If the reason for mandating SRTP is for a  
> common mode you should also decide on a key exchange mechanism. I  
> suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02 
>  for discussion on media security.


--Apple-Mail-7-428628199
Content-Disposition: attachment;
	filename=smime.p7s
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIGPTCCBjkw
ggUhoAMCAQICEC+VK1RLWxrF8KJZDR9k8p8wDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNVBAYTAlVT
MQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoTFVRoZSBVU0VS
VFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3QuY29tMTYwNAYDVQQD
Ey1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgRW1haWwwHhcNMDgwODEz
MDAwMDAwWhcNMDkwODEzMjM1OTU5WjCB4TE1MDMGA1UECxMsQ29tb2RvIFRydXN0IE5ldHdvcmsg
LSBQRVJTT05BIE5PVCBWQUxJREFURUQxRjBEBgNVBAsTPVRlcm1zIGFuZCBDb25kaXRpb25zIG9m
IHVzZTogaHR0cDovL3d3dy5jb21vZG8ubmV0L3JlcG9zaXRvcnkxHzAdBgNVBAsTFihjKTIwMDMg
Q29tb2RvIExpbWl0ZWQxFDASBgNVBAMTC0VyaWMgQnVyZ2VyMSkwJwYJKoZIhvcNAQkBFhplYnVy
Z2VyQHN0YW5kYXJkc3RyYWNrLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMTF
RRoA4LgOACMFph0aomRC/UpqoA5C/d6DUTOvTMrYSEqkjwnU4zxDtBcHlcB4AxKAov00MYsUvEU4
loz7BHjfDjv76AIkcwu33VYQbzGmarVnyaXsVb6f/cyRL3fPT0VOVO2tQAEEgwg//CX0jN8Kn2jH
uXD/HEvko7cmpL3Pwevf3+DwB61v7ca79PpEZfn/WhaqRKA4uVNPj/JbieeaLo2v/0RJzrEElZK0
pHCqxiD3mQ8ossPkA9fUCSxLlbdMcPU3be5x8vt8Q8mYTXF5Z3d9RZmYrmNkvTQtdzVpfYWr/hgV
Xqm9tByOOAR+hoN3FKbubR/OrAHL9yDAd4sCAwEAAaOCAhwwggIYMB8GA1UdIwQYMBaAFImCZ33E
nSZwAEu0UEh83j2uBG59MB0GA1UdDgQWBBRDWgutb7b8R/L7G3Y3D+molAA3VzAOBgNVHQ8BAf8E
BAMCBaAwDAYDVR0TAQH/BAIwADAgBgNVHSUEGTAXBggrBgEFBQcDBAYLKwYBBAGyMQEDBQIwEQYJ
YIZIAYb4QgEBBAQDAgUgMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQEBMCswKQYIKwYBBQUHAgEW
HWh0dHBzOi8vc2VjdXJlLmNvbW9kby5uZXQvQ1BTMIGlBgNVHR8EgZ0wgZowTKBKoEiGRmh0dHA6
Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRpb25hbmRF
bWFpbC5jcmwwSqBIoEaGRGh0dHA6Ly9jcmwuY29tb2RvLm5ldC9VVE4tVVNFUkZpcnN0LUNsaWVu
dEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMGwGCCsGAQUFBwEBBGAwXjA2BggrBgEFBQcwAoYq
aHR0cDovL2NydC5jb21vZG9jYS5jb20vVVROQUFBQ2xpZW50Q0EuY3J0MCQGCCsGAQUFBzABhhho
dHRwOi8vb2NzcC5jb21vZG9jYS5jb20wJQYDVR0RBB4wHIEaZWJ1cmdlckBzdGFuZGFyZHN0cmFj
ay5jb20wDQYJKoZIhvcNAQEFBQADggEBAGeBR7NPCvrY3GQoIi49JOuciatY2r4st905Jw1etp6J
umFFWlaCBl11tFSclk/3S45B+lUv3SEvG4CEjUByPScprVmCqHR+y8BAQaB/CV+N1y14x3MbhJ+Z
8XDGKeUXuuyGd9w0l3/t/QPid6TRXQjQFrLPFs1IALuNpNiFMHEF/xFbMG1Z2vznR/gSPlePekoZ
TqcExIDBNZTBebpZqwAXzPpedNNOclbMLFLWDMOAozVRpkfjI0eiFsk8SF1Ho1Gb9Bx8DeG4peE2
KRVOR9FFnZZgBpFjXYRcglsMOSKCY8HgE+NGvbbqbrMoBV/BlYyxRXwfti71RL9Zs2Cq1eQxggP8
MIID+AIBATCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExh
a2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8v
d3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRp
Y2F0aW9uIGFuZCBFbWFpbAIQL5UrVEtbGsXwolkNH2TynzAJBgUrDgMCGgUAoIICDTAYBgkqhkiG
9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0wOTA3MDkyMDI4MDRaMCMGCSqGSIb3
DQEJBDEWBBRC7T8KXqvYCOzBeU2QSO2QRvUbMjCB1AYJKwYBBAGCNxAEMYHGMIHDMIGuMQswCQYD
VQQGEwJVUzELMAkGA1UECBMCVVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBDaXR5MR4wHAYDVQQKExVU
aGUgVVNFUlRSVVNUIE5ldHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93d3cudXNlcnRydXN0LmNvbTE2
MDQGA1UEAxMtVVROLVVTRVJGaXJzdC1DbGllbnQgQXV0aGVudGljYXRpb24gYW5kIEVtYWlsAhAv
lStUS1saxfCiWQ0fZPKfMIHWBgsqhkiG9w0BCRACCzGBxqCBwzCBrjELMAkGA1UEBhMCVVMxCzAJ
BgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVT
VCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVU
Ti1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbAIQL5UrVEtbGsXwolkN
H2TynzANBgkqhkiG9w0BAQEFAASCAQBjSveKBHQsG/3jap4YZvyqosUcvPoVNfz5u+9tQnE4RDIA
uYj/srk5EUfJC5npCa7f2KvBDUL+qF68TIyIp2pnUi9vedSyAZH/94AwNI0rwCStuy7SCYMet9xA
JEHzJQWxDRmaGG1wt4VtIldp2f7PF0Rgn4egOMsPelMEg/hsKXVOiLvqMlqVDcaP+7jg8JvyYq9R
VImcVrmp+2OvAoDQPT1VRFHW31+fdlvPNcrDfYYPzMUY0Y1yhoV/W2gYAaZEJDt4S2D+BqgWpBDA
FGfMlIihdyEATamhQRoiCHeY57bOBErJTeQF2Hq6lhPi0b/CtgBukp2lQfD0TJm1UtHdAAAAAAAA

--Apple-Mail-7-428628199--

From AUDET@nortel.com  Thu Jul  9 13:49:16 2009
Return-Path: <AUDET@nortel.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E09093A6D37; Thu,  9 Jul 2009 13:49:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.305
X-Spam-Level: 
X-Spam-Status: No, score=-6.305 tagged_above=-999 required=5 tests=[AWL=0.294,  BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YlYnKsp5xCbN; Thu,  9 Jul 2009 13:49:16 -0700 (PDT)
Received: from zrtps0kp.nortel.com (zrtps0kp.nortel.com [47.140.192.56]) by core3.amsl.com (Postfix) with ESMTP id 1CDFB3A6D55; Thu,  9 Jul 2009 13:48:56 -0700 (PDT)
Received: from zrc2hxm0.corp.nortel.com (zrc2hxm0.corp.nortel.com [47.103.123.71]) by zrtps0kp.nortel.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id n69KnDi06199; Thu, 9 Jul 2009 20:49:13 GMT
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Date: Thu, 9 Jul 2009 15:48:56 -0500
Message-ID: <1ECE0EB50388174790F9694F77522CCF1EE8AAC1@zrc2hxm0.corp.nortel.com>
In-Reply-To: <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
Thread-Topic: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
thread-index: AcoA08qFd1S0dvASReCM8f8AHQdPFgAAoe5A
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com> <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
From: "Francois Audet" <audet@nortel.com>
To: "Eric Burger" <eburger@standardstrack.com>, "Roni Even" <Even.roni@huawei.com>
X-Mailman-Approved-At: Fri, 10 Jul 2009 08:28:56 -0700
Cc: speechsc@ietf.org, Saravanan Shanmugham <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Jul 2009 20:49:17 -0000

Eric,

I think you need to clarify the context of the following statement you=20
made: "The reality is that NO ONE has implemented any security to=20
date."

Certainly, SRTP is widely implemented and deployed in many environements
(e.g., Enteprise telephony for example).

I am assuming that your comment was specific to MRCPv2?

> -----Original Message-----
> From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On=20
> Behalf Of Eric Burger
> Sent: Thursday, July 09, 2009 13:28
> To: Roni Even
> Cc: Daniel Burnett; speechsc@ietf.org; Saravanan Shanmugham;=20
> rai@ietf.org
> Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
>=20
> The reality is that NO ONE has implemented any security to=20
> date. The GENART reviewer raised the same issue, and so far=20
> the work group has the same response: MRCPv2 (the speechsc=20
> work group) is not planning on figuring out which of the=20
> seven key exchange mechanisms to use in SIP.  We are counting=20
> on the community publishing something, and people using it. =20
> After all, we are the "using SIP for media resource control"=20
> work group, not the "media resource control work group using=20
> something like SIP for control."
>=20
> Does this work for you?
>=20
> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>=20
> > [snip]
> >
> >
> > 18.   In section 12.3 the suggestion is to use SRTP as the=20
> mandatory =20
> > interoperability mode. If the reason for mandating SRTP is for a=20
> > common mode you should also decide on a key exchange mechanism. I=20
> > suggest you look=20
> > athttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02
> >  for discussion on media security.
>=20
>=20

From Even.roni@huawei.com  Thu Jul  9 13:57:07 2009
Return-Path: <Even.roni@huawei.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AE6813A6866; Thu,  9 Jul 2009 13:57:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.556
X-Spam-Level: 
X-Spam-Status: No, score=-0.556 tagged_above=-999 required=5 tests=[AWL=-0.680, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RCVD_IN_SORBS_WEB=0.619, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id cC+1ttcJCOVH; Thu,  9 Jul 2009 13:57:07 -0700 (PDT)
Received: from szxga03-in.huawei.com (unknown [119.145.14.66]) by core3.amsl.com (Postfix) with ESMTP id CF8D23A6405; Thu,  9 Jul 2009 13:57:06 -0700 (PDT)
Received: from huawei.com (szxga03-in [172.24.2.9]) by szxga03-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KMJ0030C8VMF2@szxga03-in.huawei.com>; Fri, 10 Jul 2009 04:57:22 +0800 (CST)
Received: from huawei.com ([172.24.1.3]) by szxga03-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KMJ006CY8VMSR@szxga03-in.huawei.com>; Fri, 10 Jul 2009 04:57:22 +0800 (CST)
Received: from windows8d787f9 (bzq-79-179-66-111.red.bezeqint.net [79.179.66.111]) by szxml01-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTPA id <0KMJ001HU8VGOC@szxml01-in.huawei.com>; Fri, 10 Jul 2009 04:57:22 +0800 (CST)
Date: Thu, 09 Jul 2009 23:56:21 +0300
From: Roni Even <Even.roni@huawei.com>
In-reply-to: <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
To: 'Eric Burger' <eburger@standardstrack.com>
Message-id: <05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
MIME-version: 1.0
X-Mailer: Microsoft Office Outlook 12.0
Content-type: text/plain; charset=us-ascii
Content-language: en-us
Content-transfer-encoding: 7BIT
Thread-index: AcoA08zySVmonQexS/CVwQ8mR6VuCgAAoPQg
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com> <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>
X-Mailman-Approved-At: Fri, 10 Jul 2009 08:28:56 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Jul 2009 20:57:07 -0000

Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be  not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft

Roni

> -----Original Message-----
> From: Eric Burger [mailto:eburger@standardstrack.com]
> Sent: Thursday, July 09, 2009 11:28 PM
> To: Roni Even
> Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;
> rai@ietf.org
> Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19
> 
> The reality is that NO ONE has implemented any security to date. The
> GENART reviewer raised the same issue, and so far the work group has
> the same response: MRCPv2 (the speechsc work group) is not planning on
> figuring out which of the seven key exchange mechanisms to use in
> SIP.  We are counting on the community publishing something, and
> people using it.  After all, we are the "using SIP for media resource
> control" work group, not the "media resource control work group using
> something like SIP for control."
> 
> Does this work for you?
> 
> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
> 
> > [snip]
> >
> >
> > 18.   In section 12.3 the suggestion is to use SRTP as the mandatory
> > interoperability mode. If the reason for mandating SRTP is for a
> > common mode you should also decide on a key exchange mechanism. I
> > suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-
> not-mandatory-02
> >  for discussion on media security.



From eburger@standardstrack.com  Sat Jul 11 18:09:26 2009
Return-Path: <eburger@standardstrack.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C79023A6812; Sat, 11 Jul 2009 18:09:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jHl+FvyKw-Qa; Sat, 11 Jul 2009 18:09:26 -0700 (PDT)
Received: from gs19.inmotionhosting.com (gs19.inmotionhosting.com [205.134.252.251]) by core3.amsl.com (Postfix) with ESMTP id 0B1D93A6811; Sat, 11 Jul 2009 18:09:26 -0700 (PDT)
Received: from c-75-68-112-157.hsd1.nh.comcast.net ([75.68.112.157] helo=[192.168.45.100]) by gs19.inmotionhosting.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69) (envelope-from <eburger@standardstrack.com>) id 1MPnZ4-0004Ve-3X; Sat, 11 Jul 2009 18:09:14 -0700
Message-Id: <1C686439-B153-4C31-86CC-1F9D9FD1914E@standardstrack.com>
From: Eric Burger <eburger@standardstrack.com>
To: Francois Audet <audet@nortel.com>
In-Reply-To: <1ECE0EB50388174790F9694F77522CCF1EE8AAC1@zrc2hxm0.corp.nortel.com>
Content-Type: multipart/signed; boundary=Apple-Mail-25-618329138; micalg=sha1; protocol="application/pkcs7-signature"
Mime-Version: 1.0 (Apple Message framework v935.3)
Date: Sat, 11 Jul 2009 21:09:44 -0400
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com> <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com> <1ECE0EB50388174790F9694F77522CCF1EE8AAC1@zrc2hxm0.corp.nortel.com>
X-Mailer: Apple Mail (2.935.3)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - gs19.inmotionhosting.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - standardstrack.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
Cc: speechsc@ietf.org, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Jul 2009 01:09:26 -0000

--Apple-Mail-25-618329138
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

Correct: no one doing MRCPv2, not no one at all.

On Jul 9, 2009, at 4:48 PM, Francois Audet wrote:

> Eric,
>
> I think you need to clarify the context of the following statement you
> made: "The reality is that NO ONE has implemented any security to
> date."
>
> Certainly, SRTP is widely implemented and deployed in many  
> environements
> (e.g., Enteprise telephony for example).
>
> I am assuming that your comment was specific to MRCPv2?
>
>> -----Original Message-----
>> From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On
>> Behalf Of Eric Burger
>> Sent: Thursday, July 09, 2009 13:28
>> To: Roni Even
>> Cc: Daniel Burnett; speechsc@ietf.org; Saravanan Shanmugham;
>> rai@ietf.org
>> Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
>>
>> The reality is that NO ONE has implemented any security to
>> date. The GENART reviewer raised the same issue, and so far
>> the work group has the same response: MRCPv2 (the speechsc
>> work group) is not planning on figuring out which of the
>> seven key exchange mechanisms to use in SIP.  We are counting
>> on the community publishing something, and people using it.
>> After all, we are the "using SIP for media resource control"
>> work group, not the "media resource control work group using
>> something like SIP for control."
>>
>> Does this work for you?
>>
>> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>>
>>> [snip]
>>>
>>>
>>> 18.   In section 12.3 the suggestion is to use SRTP as the
>> mandatory
>>> interoperability mode. If the reason for mandating SRTP is for a
>>> common mode you should also decide on a key exchange mechanism. I
>>> suggest you look
>>> athttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02
>>> for discussion on media security.
>>
>>


--Apple-Mail-25-618329138
Content-Disposition: attachment;
	filename=smime.p7s
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIGPTCCBjkw
ggUhoAMCAQICEC+VK1RLWxrF8KJZDR9k8p8wDQYJKoZIhvcNAQEFBQAwga4xCzAJBgNVBAYTAlVT
MQswCQYDVQQIEwJVVDEXMBUGA1UEBxMOU2FsdCBMYWtlIENpdHkxHjAcBgNVBAoTFVRoZSBVU0VS
VFJVU1QgTmV0d29yazEhMB8GA1UECxMYaHR0cDovL3d3dy51c2VydHJ1c3QuY29tMTYwNAYDVQQD
Ey1VVE4tVVNFUkZpcnN0LUNsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgRW1haWwwHhcNMDgwODEz
MDAwMDAwWhcNMDkwODEzMjM1OTU5WjCB4TE1MDMGA1UECxMsQ29tb2RvIFRydXN0IE5ldHdvcmsg
LSBQRVJTT05BIE5PVCBWQUxJREFURUQxRjBEBgNVBAsTPVRlcm1zIGFuZCBDb25kaXRpb25zIG9m
IHVzZTogaHR0cDovL3d3dy5jb21vZG8ubmV0L3JlcG9zaXRvcnkxHzAdBgNVBAsTFihjKTIwMDMg
Q29tb2RvIExpbWl0ZWQxFDASBgNVBAMTC0VyaWMgQnVyZ2VyMSkwJwYJKoZIhvcNAQkBFhplYnVy
Z2VyQHN0YW5kYXJkc3RyYWNrLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMTF
RRoA4LgOACMFph0aomRC/UpqoA5C/d6DUTOvTMrYSEqkjwnU4zxDtBcHlcB4AxKAov00MYsUvEU4
loz7BHjfDjv76AIkcwu33VYQbzGmarVnyaXsVb6f/cyRL3fPT0VOVO2tQAEEgwg//CX0jN8Kn2jH
uXD/HEvko7cmpL3Pwevf3+DwB61v7ca79PpEZfn/WhaqRKA4uVNPj/JbieeaLo2v/0RJzrEElZK0
pHCqxiD3mQ8ossPkA9fUCSxLlbdMcPU3be5x8vt8Q8mYTXF5Z3d9RZmYrmNkvTQtdzVpfYWr/hgV
Xqm9tByOOAR+hoN3FKbubR/OrAHL9yDAd4sCAwEAAaOCAhwwggIYMB8GA1UdIwQYMBaAFImCZ33E
nSZwAEu0UEh83j2uBG59MB0GA1UdDgQWBBRDWgutb7b8R/L7G3Y3D+molAA3VzAOBgNVHQ8BAf8E
BAMCBaAwDAYDVR0TAQH/BAIwADAgBgNVHSUEGTAXBggrBgEFBQcDBAYLKwYBBAGyMQEDBQIwEQYJ
YIZIAYb4QgEBBAQDAgUgMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQEBMCswKQYIKwYBBQUHAgEW
HWh0dHBzOi8vc2VjdXJlLmNvbW9kby5uZXQvQ1BTMIGlBgNVHR8EgZ0wgZowTKBKoEiGRmh0dHA6
Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmlyc3QtQ2xpZW50QXV0aGVudGljYXRpb25hbmRF
bWFpbC5jcmwwSqBIoEaGRGh0dHA6Ly9jcmwuY29tb2RvLm5ldC9VVE4tVVNFUkZpcnN0LUNsaWVu
dEF1dGhlbnRpY2F0aW9uYW5kRW1haWwuY3JsMGwGCCsGAQUFBwEBBGAwXjA2BggrBgEFBQcwAoYq
aHR0cDovL2NydC5jb21vZG9jYS5jb20vVVROQUFBQ2xpZW50Q0EuY3J0MCQGCCsGAQUFBzABhhho
dHRwOi8vb2NzcC5jb21vZG9jYS5jb20wJQYDVR0RBB4wHIEaZWJ1cmdlckBzdGFuZGFyZHN0cmFj
ay5jb20wDQYJKoZIhvcNAQEFBQADggEBAGeBR7NPCvrY3GQoIi49JOuciatY2r4st905Jw1etp6J
umFFWlaCBl11tFSclk/3S45B+lUv3SEvG4CEjUByPScprVmCqHR+y8BAQaB/CV+N1y14x3MbhJ+Z
8XDGKeUXuuyGd9w0l3/t/QPid6TRXQjQFrLPFs1IALuNpNiFMHEF/xFbMG1Z2vznR/gSPlePekoZ
TqcExIDBNZTBebpZqwAXzPpedNNOclbMLFLWDMOAozVRpkfjI0eiFsk8SF1Ho1Gb9Bx8DeG4peE2
KRVOR9FFnZZgBpFjXYRcglsMOSKCY8HgE+NGvbbqbrMoBV/BlYyxRXwfti71RL9Zs2Cq1eQxggP8
MIID+AIBATCBwzCBrjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExh
a2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8v
d3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVUTi1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRp
Y2F0aW9uIGFuZCBFbWFpbAIQL5UrVEtbGsXwolkNH2TynzAJBgUrDgMCGgUAoIICDTAYBgkqhkiG
9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0wOTA3MTIwMTA5NDVaMCMGCSqGSIb3
DQEJBDEWBBSLjF/ijRHXRNN/J6TkgKZvLnoLLzCB1AYJKwYBBAGCNxAEMYHGMIHDMIGuMQswCQYD
VQQGEwJVUzELMAkGA1UECBMCVVQxFzAVBgNVBAcTDlNhbHQgTGFrZSBDaXR5MR4wHAYDVQQKExVU
aGUgVVNFUlRSVVNUIE5ldHdvcmsxITAfBgNVBAsTGGh0dHA6Ly93d3cudXNlcnRydXN0LmNvbTE2
MDQGA1UEAxMtVVROLVVTRVJGaXJzdC1DbGllbnQgQXV0aGVudGljYXRpb24gYW5kIEVtYWlsAhAv
lStUS1saxfCiWQ0fZPKfMIHWBgsqhkiG9w0BCRACCzGBxqCBwzCBrjELMAkGA1UEBhMCVVMxCzAJ
BgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2UgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVT
VCBOZXR3b3JrMSEwHwYDVQQLExhodHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xNjA0BgNVBAMTLVVU
Ti1VU0VSRmlyc3QtQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBFbWFpbAIQL5UrVEtbGsXwolkN
H2TynzANBgkqhkiG9w0BAQEFAASCAQBgAuiWVgljWGdb5ygWOntWgaSh9u8A4VAYaAjmK3Dy6nOa
f8Vcz5P5e5zxOfz8JbTQftb+MzXNFBx0WhZI3iEiEjObMu39vOADHIDPugxrmBqHTCWrmOggGHxu
NUsuzSgbRsqvxe46zPdXowxApucbWhzQ0rmrOS/2L7B589MRzVKCiGJK4iLjejGKZCBr7wLbBqAJ
BJe9LKV6QY3CdwV0xYemQtFEe7BY4CtMzkB5HOTKB4kuGrRq3udQNqAdTe1Uw3mOXpwtcvqBzf0j
SsgaeIkjG1qXNgBzYpPgz7fs05Nl69Hdf5LoyuXcJs0XDR6RoceufSsLdOlDbAta7yLQAAAAAAAA

--Apple-Mail-25-618329138--

From AUDET@nortel.com  Sat Jul 11 19:09:16 2009
Return-Path: <AUDET@nortel.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 060DC3A6A77; Sat, 11 Jul 2009 19:09:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.057
X-Spam-Level: 
X-Spam-Status: No, score=-5.057 tagged_above=-999 required=5 tests=[AWL=-1.125, BAYES_00=-2.599, J_CHICKENPOX_53=0.6, RCVD_IN_DNSWL_MED=-4, RCVD_NUMERIC_HELO=2.067]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ul1bIq0lOMRI; Sat, 11 Jul 2009 19:09:15 -0700 (PDT)
Received: from zcars04e.nortel.com (zcars04e.nortel.com [47.129.242.56]) by core3.amsl.com (Postfix) with ESMTP id 539CC3A68D8; Sat, 11 Jul 2009 19:08:48 -0700 (PDT)
Received: from zrc2hxm0.corp.nortel.com (zrc2hxm0.corp.nortel.com [47.103.123.71]) by zcars04e.nortel.com (Switch-2.2.0/Switch-2.2.0) with ESMTP id n6C27VE27018; Sun, 12 Jul 2009 02:07:31 GMT
Received: from 47.103.119.44 ([47.103.119.44]) by zrc2hxm0.corp.nortel.com ([47.103.119.44]) with Microsoft Exchange Server HTTP-DAV ;  Sun, 12 Jul 2009 02:04:08 +0000
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com> <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com> <1ECE0EB50388174790F9694F77522CCF1EE8AAC1@zrc2hxm0.corp.nortel.com> <1C686439-B153-4C31-86CC-1F9D9FD1914E@standardstrack.com>
Message-ID: <BD300CD9-786F-4C3B-9CD6-56526304E832@nortel.com>
From: "Francois Audet" <audet@nortel.com>
To: "Eric Burger" <eburger@standardstrack.com>
In-Reply-To: <1C686439-B153-4C31-86CC-1F9D9FD1914E@standardstrack.com>
Thread-Topic: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
thread-index: AcoClQqiv0Up8hA4Tb+dIp7jSFOHrQ==
Content-Type: text/plain; format=flowed; delsp=yes; charset="us-ascii"
Content-Transfer-Encoding: 7bit
MIME-Version: 1.0 (iPod Mail 7A341)
Date: Sat, 11 Jul 2009 19:03:54 -0700
X-Mailman-Approved-At: Sun, 12 Jul 2009 08:45:37 -0700
Cc: speechsc@ietf.org, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Jul 2009 02:09:16 -0000

Danke

On Jul 11, 2009, at 18:09, "Eric Burger" <eburger@standardstrack.com>  
wrote:

>
> --Apple-Mail-25-618329138
> Content-Type: text/plain;
>    charset=US-ASCII;
>    format=flowed;
>    delsp=yes
> Content-Transfer-Encoding: 7bit
>
> Correct: no one doing MRCPv2, not no one at all.
>
> On Jul 9, 2009, at 4:48 PM, Francois Audet wrote:
>
>> Eric,
>>
>> I think you need to clarify the context of the following statement  
>> you
>> made: "The reality is that NO ONE has implemented any security to
>> date."
>>
>> Certainly, SRTP is widely implemented and deployed in many
>> environements
>> (e.g., Enteprise telephony for example).
>>
>> I am assuming that your comment was specific to MRCPv2?
>>
>>> -----Original Message-----
>>> From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On
>>> Behalf Of Eric Burger
>>> Sent: Thursday, July 09, 2009 13:28
>>> To: Roni Even
>>> Cc: Daniel Burnett; speechsc@ietf.org; Sar

From achaloyan@yahoo.com  Tue Jul 14 02:44:24 2009
Return-Path: <achaloyan@yahoo.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 43C943A67E4 for <speechsc@core3.amsl.com>; Tue, 14 Jul 2009 02:44:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.202
X-Spam-Level: 
X-Spam-Status: No, score=-1.202 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=1.396]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bF13SQUTaD9K for <speechsc@core3.amsl.com>; Tue, 14 Jul 2009 02:44:22 -0700 (PDT)
Received: from n76.bullet.mail.sp1.yahoo.com (n76.bullet.mail.sp1.yahoo.com [98.136.44.48]) by core3.amsl.com (Postfix) with SMTP id DF6E53A68F0 for <speechsc@ietf.org>; Tue, 14 Jul 2009 02:44:22 -0700 (PDT)
Received: from [216.252.122.219] by n76.bullet.mail.sp1.yahoo.com with NNFMP; 14 Jul 2009 09:44:25 -0000
Received: from [67.195.9.82] by t4.bullet.sp1.yahoo.com with NNFMP; 14 Jul 2009 09:44:24 -0000
Received: from [67.195.9.98] by t2.bullet.mail.gq1.yahoo.com with NNFMP; 14 Jul 2009 09:44:24 -0000
Received: from [127.0.0.1] by omp102.mail.gq1.yahoo.com with NNFMP; 14 Jul 2009 09:44:24 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 704360.22074.bm@omp102.mail.gq1.yahoo.com
Received: (qmail 7838 invoked by uid 60001); 14 Jul 2009 09:44:24 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1247564664; bh=6PGtjmTXhy7iihojsv08oW5n0ww+/Jh8Xuq5Hpgw1Ds=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type; b=kjrP4kcJsGw02o2JbkYiJ0TtUHFGQsEkPiRM2ExIzl2kbXMnYm3fUSk1htmyHWoLHFi7VamT8nOD8VNYb2n0tRo97cBIo0JLdpNZoJqlYFOr1dXXoFYkGAUqkX+0GZ0GkJBUiYhcUFsvTIwKVFwHOfSxFRo8EdGw3ZJ8slaWRt4=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type; b=SSqhwA+BmdddtSmqOh9YtgAPoNjq/QKounPRHLADvW3Bwi9q6o/8BJ9HmJEwLXA5DW+ZaSZAIWTyWwTcKG6BcUac/qXvuXw6jVmlDKJsNjFtijFcqbxP79d91GYhvvP6PrIetpmpIa59C3+ikzcfjJHuI+nFJP77ZAMGdcFo160=;
Message-ID: <441543.7572.qm@web111316.mail.gq1.yahoo.com>
X-YMail-OSG: eM1wf8kVM1kaMWG0pcbN15Qa8D7mOp9TThBq1rX7mzGowibXVY.wTuOv7tmqRATaOj4f.KoL2stoj0fcg6tWPerSYc2an0xbuj0LzHrcjfF7x7zYrLXwMWRfRjoJECXT7qpPgvBp3L.zCFCIsbmFAS_AcTcz.72DSori4qT1XXjmw6rbjzPOMCzlUd1IRLroY3YRP285MXlrSKmpq2vMSR8.I2BRCboRDjdsJYyGtVOBWyo9ziJ.3CpBrhl3sI6fgE80khvFKg9fLaByPaT7sohMiHdWWFZXnLkQMn.4B_MBnfEnxggFD3QlypCj1uR6wALZ0N9tWAyt08TwsTFO7nheLMrRGv5AywZjg_gwYZh7y9_VQa68sg--
Received: from [91.198.247.201] by web111316.mail.gq1.yahoo.com via HTTP; Tue, 14 Jul 2009 02:44:23 PDT
X-Mailer: YahooMailRC/1358.21 YahooMailWebService/0.7.289.15
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
Date: Tue, 14 Jul 2009 02:44:23 -0700 (PDT)
From: Arsen Chaloyan <achaloyan@yahoo.com>
To: Roni Even <Even.roni@huawei.com>, sarvi@cisco.com, dburnett@voxeo.com
In-Reply-To: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1520693546-1247564663=:7572"
Cc: speechsc@ietf.org, oran@cisco.com, rai@ietf.org
Subject: Re: [Speechsc] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 09:44:24 -0000

--0-1520693546-1247564663=:7572
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi,=0ATwo small issues left you may want to fix.=0A=0A- Section 9.4.30=0AMe=
dia type should be "text/plain" instead of "plain/text"=0Ahttp://www.w3.org=
/TR/2004/REC-speech-synthesis-20040907/=0A=0A- Find BARGE-IN-OCCURED replac=
e with BARGE-IN-OCCURRED=0AThere are 3 such occurrences in the text.=0A=0AT=
hanks,=0AArsen.=0A=0A=0A=0A=0A________________________________=0AFrom: Roni=
 Even <Even.roni@huawei.com>=0ATo: sarvi@cisco.com; dburnett@voxeo.com=0ACc=
: speechsc@ietf.org; oran@cisco.com; rai@ietf.org=0ASent: Wednesday, July 8=
, 2009 12:40:17 AM=0ASubject: [Speechsc] RAI review of draft-ietf-speechsc-=
mrcpv2-19=0A=0A =0AHi,=0AI was=0Aassigned to do a RAI review of the draft. =
 The draft looks ready for=0Apublication to me. I have some comments mostly=
 editorial. =0AThe=0Aonly issue I see that is not pure editorial is the iss=
ue of the different=0Aparameters like confidence threshold, sensitivity lev=
el (see comments 11, 13,=0A15, 16 and 17). I think that some clarification =
on the semantics and the scale=0A(for example are the values linearly space=
d) as well as when they are useful=0Awill be helpful to implementers.=0A1. =
      In figure 1 Expand the abbreviations TTS, ASR, SV , SI=0Aand how they=
 are related to the media resource types in 3.1=0A2.       In figure 1 ther=
e is a SIP dialog between the MRCPv2=0Aclient and the media source/sink, wh=
at is this dialog, I only saw in section 4=0Aa dialog between the client an=
d server.=0A3.       In section 3.2 you have =E2=80=9CFor=0Aexample: sip:mr=
cpv2@example.net=E2=80=9D twice one after=0Athe other.=0A =0A4.       In th=
e example in section 4.2 you=0A=E2=80=9Ca=3Dcmid:1=E2=80=9D, cmid is specif=
ied later in the document so maybe you=0Acan add some reference to where it=
 is specified=0A =0A5.       In the example is section 4.2 and in=0Afollowi=
ng examples you have =E2=80=9Cm=3Daudio 49170 RTP/AVP 0 96=E2=80=9D but do =
not=0Ahave an rtpmap parameter for mapping 96 (dynamic payload type number)=
 to a=0Amedia encoding name.=0A =0A6.       In section 4.3 =E2=80=9CAlso no=
te that=0Amore that one media session can be associated with a single resou=
rce if need=0Abe, but this scenario is not useful for the current set of re=
sources=E2=80=9D.=0AThere is a typo the second =E2=80=9Cthat=E2=80=9D shoul=
d be =E2=80=9Cthan=E2=80=9D. I=0Aam also not sure if the current syntax in =
this document can support the mode.=0A =0A =0A7.       In section 4.3 =E2=
=80=9CThe formatting=0Aof the"cmid" attribute in SDP RFC3388 [RFC4566]=E2=
=80=9D. I think you=0Ameant SDP grouping and need the reference to RFC 3388=
..=0A =0A =0A8.       In section 5.1 =E2=80=9CThe message-length=0Afield spe=
cifies the length of the message, including the start-line=E2=80=9D is=0Ath=
e length in Bytes, there is no unit specified.=0A =0A9.       In section 6.=
3.1, typo you have=0A=E2=80=9CVerfication =E2=80=9C instead of verification=
.. It appears twice in the=0Asection.=0A =0A10.   In the example in section =
7 you have=0A=E2=80=9Cm=3Daudio 0 RTP/AVP 0 1 3=E2=80=9D payload type 1 was=
 deleted from the IANA=0Aregistry, maybe have another payload type number.=
=0A =0A11.   In section 9.4.1, 9.4.2 and 9.4.3=0Ayou specify confidence thr=
eshold, sensitivity level and speed vs accuracy. What=0Ais the scale here; =
is it linear between 0 and 1. What is the absolute value of=0Athe number, i=
f you receive the same confidence level from two recognizers are=0Athey the=
 same (e.g. when using context block to switch servers).  For the=0Aspeed v=
s accuracy, how does the client know what is the relation between the=0Aval=
ue and the number of available sessions, since this seems to be the reason=
=0Afor using this parameter.=0A =0A12.   In 9.4.9 and in 10.4.8, 11.4.11 wh=
at=0Aare the values for media-type-value, you also mention audio and video =
but it=0Alooks to me that this document only discusses voice.=0A =0A13.   I=
n 9.4.35 and 9.4.36 what is the=0Ascale for the consistency here. How does =
one know what close means. What is the=0Aconsistency between different reco=
gnizers.=0A =0A14.   In section 9.6.3.3 in the example=0A(figure 2) confide=
nce should be 0.75 and not 75=0A =0A15.   In section 10.4.1 it is not clear=
=0Ahow you measure the sensitivity in order to specify, is it based on some=
 SNR=0Atranslated to 0 to 1 scale?=0A =0A16.   In 11.4.6 the same issue wit=
h the=0Ascale, how does the client know how to set a value when working wit=
h different=0Aspeaker verification servers.=0A =0A17.   In 11.5.2.9 you sta=
te that the=0Averification-score is not a probability, so what is it. How c=
an the client decide=0Aif, for example, 0 is a good score for specifying th=
e threshold.  I also=0Anoticed that the values in the example in section 11=
..5.2.10 are very precise=0Alike 0.98514 is this the expected precision. The=
 examples here and in section=0A11.11 do not show the threshold, if the thr=
eshold is required for this flow why=0Anot show it in the example?=0A =0A18=
..   In section 12.3 the suggestion is to=0Ause SRTP as the mandatory intero=
perability mode. If the reason for mandating=0ASRTP is for a common mode yo=
u should also decide on a key exchange mechanism. I=0Asuggest you look at h=
ttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-02 for discussi=
on on media security.=0A =0A19.   In section13.7.2 you specify the attribut=
e=0Aresource as session level yet in the example in section 4.2 it is a med=
ia level=0Aattribute. The same goes for the channel attribute=0A =0AThanks=
=0A =0ARoni=0AEven
--0-1520693546-1247564663=:7572
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><style type=3D"text/css"><!-- DIV {margin:0px;} --></style></he=
ad><body><div style=3D"font-family:arial,helvetica,sans-serif;font-size:10p=
t"><div>Hi,<br>Two small issues left you may want to fix.<br><br>- Section =
9.4.30<br>Media type should be "text/plain" instead of "plain/text"<br><spa=
n><a target=3D"_blank" href=3D"http://www.w3.org/TR/2004/REC-speech-synthes=
is-20040907/">http://www.w3.org/TR/2004/REC-speech-synthesis-20040907/</a><=
/span><br><br>- Find BARGE-IN-OCCURED replace with BARGE-IN-OCCURRED<br>The=
re are 3 such occurrences in the text.<br><br>Thanks,<br>Arsen.<br></div><d=
iv style=3D"font-family: arial,helvetica,sans-serif; font-size: 10pt;"><br>=
<div style=3D"font-family: times new roman,new york,times,serif; font-size:=
 12pt;"><font size=3D"2" face=3D"Tahoma"><hr size=3D"1"><b><span style=3D"f=
ont-weight: bold;">From:</span></b> Roni Even &lt;Even.roni@huawei.com&gt;<=
br><b><span style=3D"font-weight: bold;">To:</span></b> sarvi@cisco.com;
 dburnett@voxeo.com<br><b><span style=3D"font-weight: bold;">Cc:</span></b>=
 speechsc@ietf.org; oran@cisco.com; rai@ietf.org<br><b><span style=3D"font-=
weight: bold;">Sent:</span></b> Wednesday, July 8, 2009 12:40:17 AM<br><b><=
span style=3D"font-weight: bold;">Subject:</span></b> [Speechsc] RAI review=
 of draft-ietf-speechsc-mrcpv2-19<br></font><br>=0A=0A=0A=0A =0A =0A<style>=
=0A<!--=0A =0A _filtered {font-family:"Cambria Math";panose-1:2 4 5 3 5 4 6=
 3 2 4;}=0A _filtered {font-family:Calibri;panose-1:2 15 5 2 2 2 4 3 2 4;}=
=0A _filtered {font-family:Consolas;panose-1:2 11 6 9 2 2 4 3 2 4;}=0A =0Ap=
..MsoNormal, li.MsoNormal, div.MsoNormal=0A=09{margin:0in;margin-bottom:.000=
1pt;font-size:11.0pt;font-family:"Calibri", "sans-serif";}=0Ap.MsoCommentTe=
xt, li.MsoCommentText, div.MsoCommentText=0A=09{margin-top:0in;margin-right=
:0in;margin-bottom:10.0pt;margin-left:0in;line-height:115%;font-size:10.0pt=
;font-family:"Calibri", "sans-serif";}=0Aa:link, span.MsoHyperlink=0A=09{co=
lor:blue;text-decoration:underline;}=0Aa:visited, span.MsoHyperlinkFollowed=
=0A=09{color:purple;text-decoration:underline;}=0Ap.MsoPlainText, li.MsoPla=
inText, div.MsoPlainText=0A=09{margin:0in;margin-bottom:.0001pt;font-size:1=
0.5pt;font-family:Consolas;}=0Ap.MsoListParagraph, li.MsoListParagraph, div=
..MsoListParagraph=0A=09{margin-top:0in;margin-right:0in;margin-bottom:0in;m=
argin-left:.5in;margin-bottom:.0001pt;font-size:11.0pt;font-family:"Calibri=
", "sans-serif";}=0Aspan.EmailStyle17=0A=09{font-family:"Calibri", "sans-se=
rif";color:windowtext;}=0Aspan.CommentTextChar=0A=09{font-family:"Calibri",=
 "sans-serif";}=0Aspan.PlainTextChar=0A=09{font-family:Consolas;}=0A.MsoChp=
Default=0A=09{}=0A _filtered {margin:1.0in 1.25in 1.0in 1.25in;}=0Adiv.Sect=
ion1=0A=09{}=0A =0A _filtered {}=0A _filtered {}=0A _filtered {}=0A _filter=
ed {}=0A _filtered {}=0A _filtered {}=0A _filtered {}=0A _filtered {}=0A _f=
iltered {}=0A _filtered {}=0Aol=0A=09{margin-bottom:0in;}=0Aul=0A=09{margin=
-bottom:0in;}=0A-->=0A</style>=0A=0A=0A=0A<div class=3D"Section1">=0A=0A<p =
class=3D"MsoCommentText"><span style=3D"font-size: 11pt; line-height: 115%;=
">Hi,</span></p> =0A=0A<p class=3D"MsoCommentText"><span style=3D"font-size=
: 11pt; line-height: 115%;">I was=0Aassigned to do a RAI review of the draf=
t. &nbsp;The draft looks ready for=0Apublication to me. I have some comment=
s mostly editorial. </span></p> =0A=0A<p class=3D"MsoCommentText"><span sty=
le=3D"font-size: 11pt; line-height: 115%;">The=0Aonly issue I see that is n=
ot pure editorial is the issue of the different=0Aparameters like confidenc=
e threshold, sensitivity level (see comments 11, 13,=0A15, 16 and 17). I th=
ink that some clarification on the semantics and the scale=0A(for example a=
re the values linearly spaced) as well as when they are useful=0Awill be he=
lpful to implementers.</span></p> =0A=0A<p class=3D"MsoCommentText" style=
=3D"margin-left: 0.5in;"><span style=3D"font-size: 11pt; line-height: 115%;=
"><span style=3D"">1.<span style=3D"font-family: &quot;Times New Roman&quot=
;; font-style: normal; font-variant: normal; font-weight: normal; font-size=
: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -=
x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=0A</span></span>=
</span><span dir=3D"ltr"></span><span style=3D"font-size: 11pt; line-height=
: 115%;">In figure 1 Expand the abbreviations TTS, ASR, SV , SI=0Aand how t=
hey are related to the media resource types in 3.1</span></p> =0A=0A<p clas=
s=3D"MsoCommentText" style=3D"margin-left: 0.5in;"><span style=3D"font-size=
: 11pt; line-height: 115%;"><span style=3D"">2.<span style=3D"font-family: =
&quot;Times New Roman&quot;; font-style: normal; font-variant: normal; font=
-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: non=
e; font-stretch: normal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D"fo=
nt-size: 11pt; line-height: 115%;">In figure 1 there is a SIP dialog betwee=
n the MRCPv2=0Aclient and the media source/sink, what is this dialog, I onl=
y saw in section 4=0Aa dialog between the client and server.</span></p> =0A=
=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span style=3D"f=
ont-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><=
span style=3D"">3.<span style=3D"font-family: &quot;Times New Roman&quot;; =
font-style: normal; font-variant: normal; font-weight: normal; font-size: 7=
pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-s=
ystem-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=0A</span></span></s=
pan><span dir=3D"ltr"></span><span style=3D"font-size: 11pt; font-family: &=
quot;Calibri&quot;,&quot;sans-serif&quot;;">In section 3.2 you have =E2=80=
=9CFor=0Aexample: <a rel=3D"nofollow"><span style=3D"color: windowtext; tex=
t-decoration: none;">sip:mrcpv2@example.net</span></a>=E2=80=9D twice one a=
fter=0Athe other.</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D=
"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"=
> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0=
..5in;"><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&qu=
ot;sans-serif&quot;;"><span style=3D"">4.<span style=3D"font-family: &quot;=
Times New Roman&quot;; font-style: normal; font-variant: normal; font-weigh=
t: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; fon=
t-stretch: normal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D"font-siz=
e: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In the e=
xample in section 4.2 you=0A=E2=80=9Ca=3Dcmid:1=E2=80=9D, cmid is specified=
 later in the document so maybe you=0Acan add some reference to where it is=
 specified</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-s=
ize: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp=
;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;">=
<span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans=
-serif&quot;;"><span style=3D"">5.<span style=3D"font-family: &quot;Times N=
ew Roman&quot;; font-style: normal; font-variant: normal; font-weight: norm=
al; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stret=
ch: normal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=0A<=
/span></span></span><span dir=3D"ltr"></span><span style=3D"font-size: 11pt=
; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In the example =
is section 4.2 and in=0Afollowing examples you have =E2=80=9Cm=3Daudio 4917=
0 RTP/AVP 0 96=E2=80=9D but do not=0Ahave an rtpmap parameter for mapping 9=
6 (dynamic payload type number) to a=0Amedia encoding name.</span></p> =0A=
=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-family: &=
quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p cla=
ss=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span style=3D"font-size:=
 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span styl=
e=3D"">6.<span style=3D"font-family: &quot;Times New Roman&quot;; font-styl=
e: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-=
height: normal; font-size-adjust: none; font-stretch: normal; -x-system-fon=
t: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=0A</span></span></span><span=
 dir=3D"ltr"></span><span style=3D"font-size: 11pt; font-family: &quot;Cali=
bri&quot;,&quot;sans-serif&quot;;">In section 4.3 =E2=80=9CAlso note that=
=0Amore that one media session can be associated with a single resource if =
need=0Abe, but this scenario is not useful for the current set of resources=
=E2=80=9D.=0AThere is a typo the second =E2=80=9Cthat=E2=80=9D should be =
=E2=80=9Cthan=E2=80=9D. I=0Aam also not sure if the current syntax in this =
document can support the mode.</span></p> =0A=0A<p class=3D"MsoPlainText"><=
span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-=
serif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainText"><span styl=
e=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quo=
t;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-lef=
t: 0.5in;"><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;=
,&quot;sans-serif&quot;;"><span style=3D"">7.<span style=3D"font-family: &q=
uot;Times New Roman&quot;; font-style: normal; font-variant: normal; font-w=
eight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none;=
 font-stretch: normal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D"font=
-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In s=
ection 4.3 =E2=80=9CThe formatting=0Aof the"cmid" attribute in SDP RFC3388 =
[RFC4566]=E2=80=9D. I think you=0Ameant SDP grouping and need the reference=
 to RFC 3388.</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"fon=
t-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &n=
bsp;</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 1=
1pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</spa=
n></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span =
style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif=
&quot;;"><span style=3D"">8.<span style=3D"font-family: &quot;Times New Rom=
an&quot;; font-style: normal; font-variant: normal; font-weight: normal; fo=
nt-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: no=
rmal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=0A</span>=
</span></span><span dir=3D"ltr"></span><span style=3D"font-size: 11pt; font=
-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In section 5.1 =E2=80=
=9C</span><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,=
&quot;sans-serif&quot;;">The message-length=0Afield specifies the length of=
 the message, including the start-line=E2=80=9D is=0Athe length in Bytes, t=
here is no unit specified.</span></p> =0A=0A<p class=3D"MsoPlainText"><span=
 style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-seri=
f&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margi=
n-left: 0.5in;"><span style=3D"font-size: 11pt; font-family: &quot;Calibri&=
quot;,&quot;sans-serif&quot;;"><span style=3D"">9.<span style=3D"font-famil=
y: &quot;Times New Roman&quot;; font-style: normal; font-variant: normal; f=
ont-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: =
none; font-stretch: normal; -x-system-font: none;">&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D=
"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"=
>In section 6.3.1, typo you have=0A=E2=80=9CVerfication =E2=80=9C instead o=
f verification. It appears twice in the=0Asection.</span></p> =0A=0A<p clas=
s=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-family: &quot;Calib=
ri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoP=
lainText" style=3D"margin-left: 0.5in;"><span style=3D"font-size: 11pt; fon=
t-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span style=3D"">10.=
<span style=3D"font-family: &quot;Times New Roman&quot;; font-style: normal=
; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: n=
ormal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"=
>&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=
=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot=
;;">In the example in section 7 you have=0A=E2=80=9Cm=3Daudio 0 RTP/AVP 0 1=
 3=E2=80=9D payload type 1 was deleted from the IANA=0Aregistry, maybe have=
 another payload type number.</span></p> =0A=0A<p class=3D"MsoPlainText"><s=
pan style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-s=
erif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"ma=
rgin-left: 0.5in;"><span style=3D"font-size: 11pt; font-family: &quot;Calib=
ri&quot;,&quot;sans-serif&quot;;"><span style=3D"">11.<span style=3D"font-f=
amily: &quot;Times New Roman&quot;; font-style: normal; font-variant: norma=
l; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adju=
st: none; font-stretch: normal; -x-system-font: none;">&nbsp;&nbsp;=0A</spa=
n></span></span><span dir=3D"ltr"></span><span style=3D"font-size: 11pt; fo=
nt-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In section 9.4.1, 9=
..4.2 and 9.4.3=0Ayou specify confidence threshold, sensitivity level and sp=
eed vs accuracy. What=0Ais the scale here; is it linear between 0 and 1. Wh=
at is the absolute value of=0Athe number, if you receive the same confidenc=
e level from two recognizers are=0Athey the same (e.g. when using context b=
lock to switch servers).&nbsp; For the=0Aspeed vs accuracy, how does the cl=
ient know what is the relation between the=0Avalue and the number of availa=
ble sessions, since this seems to be the reason=0Afor using this parameter.=
</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt;=
 font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></=
p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span styl=
e=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quo=
t;;"><span style=3D"">12.<span style=3D"font-family: &quot;Times New Roman&=
quot;; font-style: normal; font-variant: normal; font-weight: normal; font-=
size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: norma=
l; -x-system-font: none;">&nbsp;&nbsp;=0A</span></span></span><span dir=3D"=
ltr"></span><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot=
;,&quot;sans-serif&quot;;">In 9.4.9 and in 10.4.8, 11.4.11 what=0Aare the v=
alues for media-type-value, you also mention audio and video but it=0Alooks=
 to me that this document only discusses voice.</span></p> =0A=0A<p class=
=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-family: &quot;Calibr=
i&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPl=
ainText" style=3D"margin-left: 0.5in;"><span style=3D"font-size: 11pt; font=
-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span style=3D"">13.<=
span style=3D"font-family: &quot;Times New Roman&quot;; font-style: normal;=
 font-variant: normal; font-weight: normal; font-size: 7pt; line-height: no=
rmal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;">=
&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D=
"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"=
>In 9.4.35 and 9.4.36 what is the=0Ascale for the consistency here. How doe=
s one know what close means. What is the=0Aconsistency between different re=
cognizers.</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-s=
ize: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp=
;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;">=
<span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans=
-serif&quot;;"><span style=3D"">14.<span style=3D"font-family: &quot;Times =
New Roman&quot;; font-style: normal; font-variant: normal; font-weight: nor=
mal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stre=
tch: normal; -x-system-font: none;">&nbsp;&nbsp;=0A</span></span></span><sp=
an dir=3D"ltr"></span><span style=3D"font-size: 11pt; font-family: &quot;Ca=
libri&quot;,&quot;sans-serif&quot;;">In section 9.6.3.3 in the example=0A(f=
igure 2) confidence should be 0.75 and not 75</span></p> =0A=0A<p class=3D"=
MsoPlainText"><span style=3D"font-size: 11pt; font-family: &quot;Calibri&qu=
ot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"MsoPlainT=
ext" style=3D"margin-left: 0.5in;"><span style=3D"font-size: 11pt; font-fam=
ily: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span style=3D"">15.<span=
 style=3D"font-family: &quot;Times New Roman&quot;; font-style: normal; fon=
t-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal=
; font-size-adjust: none; font-stretch: normal; -x-system-font: none;">&nbs=
p;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span style=3D"fon=
t-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">In =
section 10.4.1 it is not clear=0Ahow you measure the sensitivity in order t=
o specify, is it based on some SNR=0Atranslated to 0 to 1 scale?</span></p>=
 =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-famil=
y: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p=
 class=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span style=3D"font-s=
ize: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span =
style=3D"">16.<span style=3D"font-family: &quot;Times New Roman&quot;; font=
-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; =
line-height: normal; font-size-adjust: none; font-stretch: normal; -x-syste=
m-font: none;">&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span=
><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;san=
s-serif&quot;;">In 11.4.6 the same issue with the=0Ascale, how does the cli=
ent know how to set a value when working with different=0Aspeaker verificat=
ion servers.</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font=
-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nb=
sp;</span></p> =0A=0A<p class=3D"MsoPlainText" style=3D"margin-left: 0.5in;=
"><span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sa=
ns-serif&quot;;"><span style=3D"">17.<span style=3D"font-family: &quot;Time=
s New Roman&quot;; font-style: normal; font-variant: normal; font-weight: n=
ormal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-st=
retch: normal; -x-system-font: none;">&nbsp;&nbsp;=0A</span></span></span><=
span dir=3D"ltr"></span><span style=3D"font-size: 11pt; font-family: &quot;=
Calibri&quot;,&quot;sans-serif&quot;;">In 11.5.2.9 you state that the=0Aver=
ification-score is not a probability, so what is it. How can the client dec=
ide=0Aif, for example, 0 is a good score for specifying the threshold.&nbsp=
; I also=0Anoticed that the values in the example in section 11.5.2.10 are =
very precise=0Alike 0.98514 is this the expected precision. The examples he=
re and in section=0A11.11 do not show the threshold, if the threshold is re=
quired for this flow why=0Anot show it in the example?</span></p> =0A=0A<p =
class=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-family: &quot;C=
alibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p class=3D"=
MsoPlainText" style=3D"margin-left: 0.5in;"><span style=3D"font-size: 11pt;=
 font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span style=3D""=
>18.<span style=3D"font-family: &quot;Times New Roman&quot;; font-style: no=
rmal; font-variant: normal; font-weight: normal; font-size: 7pt; line-heigh=
t: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: no=
ne;">&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span><span sty=
le=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&qu=
ot;;"><span>In section 12.3 the suggestion is to=0Ause SRTP as the mandator=
y interoperability mode. If the reason for mandating=0ASRTP is for a common=
 mode you should also decide on a key exchange mechanism. I=0Asuggest you l=
ook at <a target=3D"_blank" href=3D"http://tools.ietf.org/html/draft-ietf-a=
vt-srtp-not-mandatory-02">http://tools.ietf.org/html/draft-ietf-avt-srtp-no=
t-mandatory-02</a>=0Afor discussion on media security.</span></span></p> =
=0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-family=
: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A<p =
class=3D"MsoPlainText" style=3D"margin-left: 0.5in;"><span style=3D"font-si=
ze: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"><span s=
tyle=3D"">19.<span style=3D"font-family: &quot;Times New Roman&quot;; font-=
style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; l=
ine-height: normal; font-size-adjust: none; font-stretch: normal; -x-system=
-font: none;">&nbsp;&nbsp;=0A</span></span></span><span dir=3D"ltr"></span>=
<span style=3D"font-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans=
-serif&quot;;">In section13.7.2 you specify the attribute=0Aresource as ses=
sion level yet in the example in section 4.2 it is a media level=0Aattribut=
e. The same goes for the channel attribute</span></p> =0A=0A<p class=3D"Mso=
ListParagraph"> &nbsp;</p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"f=
ont-size: 11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">T=
hanks</span></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: =
11pt; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</sp=
an></p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt; fon=
t-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">Roni=0AEven</span></=
p> =0A=0A<p class=3D"MsoPlainText"><span style=3D"font-size: 11pt; font-fam=
ily: &quot;Calibri&quot;,&quot;sans-serif&quot;;"> &nbsp;</span></p> =0A=0A=
<p class=3D"MsoNormal"> &nbsp;</p> =0A=0A</div>=0A=0A</div></div></div></bo=
dy></html>
--0-1520693546-1247564663=:7572--


From dyork@voxeo.com  Tue Jul 14 13:27:14 2009
Return-Path: <dyork@voxeo.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 90F0E3A67E2; Tue, 14 Jul 2009 13:27:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id db3gDZjUuEQ9; Tue, 14 Jul 2009 13:27:13 -0700 (PDT)
Received: from voxeo.com (mmail.voxeo.com [66.193.54.208]) by core3.amsl.com (Postfix) with SMTP id 6A7BF3A67D3; Tue, 14 Jul 2009 13:27:12 -0700 (PDT)
Received: from [66.65.229.48] (account dyork HELO pc-00148.lodestar2.local) by voxeo.com (CommuniGate Pro SMTP 5.2.3) with ESMTPSA id 49415385; Tue, 14 Jul 2009 20:16:18 +0000
Message-Id: <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com>
From: Dan York <dyork@voxeo.com>
To: Roni Even <Even.roni@huawei.com>
In-Reply-To: <05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-146-859920856
Mime-Version: 1.0 (Apple Message framework v930.3)
Date: Tue, 14 Jul 2009 16:16:16 -0400
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com> <EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com> <05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com>
X-Mailer: Apple Mail (2.930.3)
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 20:27:14 -0000

--Apple-Mail-146-859920856
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

Roni,

The current text at http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 
  is:
------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support  
SRTP for protection of audio media sessions. MRCPv2 clients that  
originate or consume audio similarly MUST support SRTP. Alternative  
media channel protection MAY be used if desired (e.g. IPSEC).
------

Based on your comments and the srtp-not-mandatory draft (which was  
just revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03 
  ), my understanding would be that you are advocating something more  
like this:

------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support a  
security mechanism for protection of audio media sessions. MRCPv2  
clients that originate or consume audio similarly MUST support a  
security mechanism for protection of the audio.
------

Is that an accurate summary of your feedback?  Would that text be  
acceptable?

Regards,
Dan

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:

> Eric,
> My comment is that in this case in AVT we say that you do not need to
> mandate SRTP but mandate a security mechanism that can be  not only  
> SRTP but
> in a different layer like ipsec. This is why I gave a reference to the
> srtp-not-mandatory draft
>
> Roni
>
>> -----Original Message-----
>> From: Eric Burger [mailto:eburger@standardstrack.com]
>> Sent: Thursday, July 09, 2009 11:28 PM
>> To: Roni Even
>> Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;
>> rai@ietf.org
>> Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19
>>
>> The reality is that NO ONE has implemented any security to date. The
>> GENART reviewer raised the same issue, and so far the work group has
>> the same response: MRCPv2 (the speechsc work group) is not planning  
>> on
>> figuring out which of the seven key exchange mechanisms to use in
>> SIP.  We are counting on the community publishing something, and
>> people using it.  After all, we are the "using SIP for media resource
>> control" work group, not the "media resource control work group using
>> something like SIP for control."
>>
>> Does this work for you?
>>
>> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>>
>>> [snip]
>>>
>>>
>>> 18.   In section 12.3 the suggestion is to use SRTP as the mandatory
>>> interoperability mode. If the reason for mandating SRTP is for a
>>> common mode you should also decide on a key exchange mechanism. I
>>> suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-
>> not-mandatory-02
>>> for discussion on media security.
>
>
> _______________________________________________
> RAI mailing list
> RAI@ietf.org
> https://www.ietf.org/mailman/listinfo/rai

-- 
Dan York, Director of Conversations
Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com
Phone: +1-407-455-5859    Skype: danyork

Join the Voxeo conversation:
Blogs: http://blogs.voxeo.com
Twitter: http://twitter.com/voxeo  http://twitter.com/danyork
Facebook: http://www.facebook.com/voxeo









--Apple-Mail-146-859920856
Content-Type: text/html;
	charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

<html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
-webkit-line-break: after-white-space; =
"><div>Roni,</div><div><br></div><div>The current text at&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-1=
2.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3=
</a> is:</div><div><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: =
normal;">------</span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">12.3.  Media session =
protection&nbsp;
   </span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">Sensitive data is also =
carried on media sessions terminating on
   MRCPv2 servers (the other end of a media channel may or may not be on
   the MRCPv2 client).  This data includes the user's spoken utterances
   and the output of text-to-speech operations.  MRCPv2 servers MUST
   support SRTP for protection of audio media sessions.  MRCPv2 clients
   that originate or consume audio similarly MUST support SRTP.
   Alternative media channel protection MAY be used if desired (e.g.
   IPSEC).</span></font>
</pre></div><div>------</div><div><br></div><div>Based on your comments =
and the srtp-not-mandatory draft (which was just revised to&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">h=
ttp://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a> ), my =
understanding would be that you are advocating something more like =
this:</div><div><br></div><div>------</div><div><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"white-space: normal; ">12.3. Media =
session protection&nbsp;</span></font></pre><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"white-space: normal; ">Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></font></pre></div><div>------</div><div><br></div><div=
>Is that an accurate summary of your feedback? &nbsp;Would that text be =
acceptable?</div><div><br></div><div>Regards,</div><div>Dan</div><div><br>=
<div><div>On Jul 9, 2009, at 4:56 PM, Roni Even wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div>Eric,<br>My comment is that in this case in AVT we =
say that you do not need to<br>mandate SRTP but mandate a security =
mechanism that can be &nbsp;not only SRTP but<br>in a different layer =
like ipsec. This is why I gave a reference to the<br>srtp-not-mandatory =
draft<br><br>Roni<br><br><blockquote type=3D"cite">-----Original =
Message-----<br></blockquote><blockquote type=3D"cite">From: Eric Burger =
[<a =
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.c=
om</a>]<br></blockquote><blockquote type=3D"cite">Sent: Thursday, July =
09, 2009 11:28 PM<br></blockquote><blockquote type=3D"cite">To: Roni =
Even<br></blockquote><blockquote type=3D"cite">Cc: Saravanan Shanmugham; =
Daniel Burnett; <a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<br></blockquote><=
blockquote type=3D"cite"><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><br></blockquote><blockquote =
type=3D"cite">Subject: Re: RAI review of =
draft-ietf-speechsc-mrcpv2-19<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">The reality is =
that NO ONE has implemented any security to date. =
The<br></blockquote><blockquote type=3D"cite">GENART reviewer raised the =
same issue, and so far the work group has<br></blockquote><blockquote =
type=3D"cite">the same response: MRCPv2 (the speechsc work group) is not =
planning on<br></blockquote><blockquote type=3D"cite">figuring out which =
of the seven key exchange mechanisms to use =
in<br></blockquote><blockquote type=3D"cite">SIP. &nbsp;We are counting =
on the community publishing something, and<br></blockquote><blockquote =
type=3D"cite">people using it. &nbsp;After all, we are the "using SIP =
for media resource<br></blockquote><blockquote type=3D"cite">control" =
work group, not the "media resource control work group =
using<br></blockquote><blockquote type=3D"cite">something like SIP for =
control."<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">Does this work =
for you?<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite">On Jul 7, 2009, =
at 3:40 PM, Roni Even wrote:<br></blockquote><blockquote =
type=3D"cite"><br></blockquote><blockquote type=3D"cite"><blockquote =
type=3D"cite">[snip]<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote =
type=3D"cite"><br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote =
type=3D"cite"><br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">18. &nbsp;&nbsp;In section 12.3 =
the suggestion is to use SRTP as the =
mandatory<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">interoperability mode. If the =
reason for mandating SRTP is for =
a<br></blockquote></blockquote><blockquote type=3D"cite"><blockquote =
type=3D"cite">common mode you should also decide on a key exchange =
mechanism. I<br></blockquote></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite">suggest you look at<a =
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.ietf=
.org/html/draft-ietf-avt-srtp-</a><br></blockquote></blockquote><blockquot=
e type=3D"cite">not-mandatory-02<br></blockquote><blockquote =
type=3D"cite"><blockquote type=3D"cite"> for discussion on media =
security.<br></blockquote></blockquote><br><br>___________________________=
____________________<br>RAI mailing list<br><a =
href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>https://www.ietf.org/mail=
man/listinfo/rai<br></div></blockquote></div><br><div =
apple-content-edited=3D"true"> <span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; -webkit-border-horizontal-spacing: =
0px; -webkit-border-vertical-spacing: 0px; color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; -webkit-text-decorations-in-effect: none; =
text-indent: 0px; -webkit-text-size-adjust: auto; text-transform: none; =
orphans: 2; white-space: normal; widows: 2; word-spacing: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">--&nbsp;</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Dan York, =
Director of Conversations</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Voxeo =
Corporation<span =
class=3D"Apple-converted-space">&nbsp;</span>&nbsp;&nbsp;<a =
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Phone: +1-407-455-5859&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;&nbsp;&nbsp;</span>Skype: =
danyork&nbsp;<span class=3D"Apple-converted-space">&nbsp;</span></div><div=
 style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Join the Voxeo conversation:</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a> &nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></div><d=
iv style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a></=
div></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
12px/normal Helvetica; min-height: 14px; "><br =
class=3D"khtml-block-placeholder"></div><br =
class=3D"Apple-interchange-newline"></span></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"> </div><br></div></body></html>=

--Apple-Mail-146-859920856--

From ron.even.tlv@gmail.com  Tue Jul 14 13:56:56 2009
Return-Path: <ron.even.tlv@gmail.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id EFA6C3A68F3; Tue, 14 Jul 2009 13:56:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.12
X-Spam-Level: 
X-Spam-Status: No, score=-2.12 tagged_above=-999 required=5 tests=[AWL=0.478,  BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9H75WHTzQNi6; Tue, 14 Jul 2009 13:56:55 -0700 (PDT)
Received: from mail-bw0-f228.google.com (mail-bw0-f228.google.com [209.85.218.228]) by core3.amsl.com (Postfix) with ESMTP id 541A73A6851; Tue, 14 Jul 2009 13:56:53 -0700 (PDT)
Received: by bwz28 with SMTP id 28so1034595bwz.37 for <multiple recipients>; Tue, 14 Jul 2009 13:55:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:from:to:cc:references :in-reply-to:subject:date:message-id:mime-version:content-type :x-mailer:thread-index:content-language; bh=JXBuGNY13Nyu1sy0p+Wp+49jE5Gkdyp/do+/prc/r2A=; b=hiYsj2q4nLgbmfLoJBdnn/N+QPbZA8W4H3ECq5yEpo0wEHMizUgCUikGUODvtODG2Z G+lp04JAPEl4+2xaQNlnJa2EAcdBNZGiYAaGg/FbDpUQOvYzGErRwfI3EFM2QEIrpGM5 0PSsVWsdRu1W9f8EIcgYceM+lWdolRA5XpCdA=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:content-type:x-mailer:thread-index:content-language; b=w19DpgoWUL7PFQEVQvVlHyJ2VdCvI7hQSBkrc6/jkm7gLdRqDp8/KRhBazipYD3j+q 9THXVKs4koAwBxOdeyMaN+l/zhRsgrV9/fzDAHG8oyuMw3EieLhTuyHA3GUA0ZSX2wbj kBMW406u7SLdbjMvU9bRh2aRQ0NDy2jKR+Wqs=
Received: by 10.103.233.11 with SMTP id k11mr3670845mur.42.1247604955582; Tue, 14 Jul 2009 13:55:55 -0700 (PDT)
Received: from windows8d787f9 (bzq-79-179-66-37.red.bezeqint.net [79.179.66.37]) by mx.google.com with ESMTPS id 25sm23845825mul.20.2009.07.14.13.55.53 (version=TLSv1/SSLv3 cipher=RC4-MD5); Tue, 14 Jul 2009 13:55:54 -0700 (PDT)
From: "Roni Even" <ron.even.tlv@gmail.com>
To: "'Dan York'" <dyork@voxeo.com>, "'Roni Even'" <Even.roni@huawei.com>
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>	<EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>	<05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com> <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com>
In-Reply-To: <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com>
Date: Tue, 14 Jul 2009 23:55:27 +0300
Message-ID: <4a5cf0da.190c660a.3ec0.58fa@mx.google.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0A5D_01CA04DE.90AD2E80"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcoEwZDrIBeDdtFURVOXNaXHDHQ5wQAA1HiA
Content-Language: en-us
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 20:56:57 -0000

This is a multi-part message in MIME format.

------=_NextPart_000_0A5D_01CA04DE.90AD2E80
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Dan,

This is the general idea. The major reason is that there are various ways to
protect the data and if you are not mandating one for interoperability then
it can be more general

 

For example we have the following text when discussing security in the RTP
payloads specifications.

 

RTP packets using the payload format defined in this specification

   are subject to the security considerations discussed in the RTP

   specification [RFC3550] and any appropriate RTP profile.  The main

   security considerations for the RTP packet carrying the RTP payload

   format defined within this memo are confidentiality, integrity, and

   source authenticity.  Confidentiality is achieved by encryption of

   the RTP payload.  Integrity of the RTP packets is achieved through a

   suitable cryptographic integrity protection mechanism.  Such a

   cryptographic system may also allow the authentication of the source

   of the payload.  A suitable security mechanism for this RTP payload

   format should provide confidentiality, integrity protection, and at

   least source authentication capable of determining if an RTP packet

   is from a member of the RTP session.

 

   Note that the appropriate mechanism to provide security to RTP and

   payloads following this memo may vary.  It is dependent on the

   application, the transport, and the signaling protocol employed.

   Therefore, a single mechanism is not sufficient, although if

   suitable, usage of the Secure Real-time Transport Protocol (SRTP)

   [RFC3711] recommended.  Other mechanisms that may be used are IPsec

   [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over TCP);

   other alternatives may exist.

 

Roni Even

 

From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On Behalf Of Dan
York
Sent: Tuesday, July 14, 2009 11:16 PM
To: Roni Even
Cc: 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham';
rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

The current text at
http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 is:

------
12.3. Media session protection  
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances and the output of
text-to-speech operations. MRCPv2 servers MUST support SRTP for protection
of audio media sessions. MRCPv2 clients that originate or consume audio
similarly MUST support SRTP. Alternative media channel protection MAY be
used if desired (e.g. IPSEC).

------

 

Based on your comments and the srtp-not-mandatory draft (which was just
revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03
), my understanding would be that you are advocating something more like
this:

 

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Is that an accurate summary of your feedback?  Would that text be
acceptable?

 

Regards,

Dan

 

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:





Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be  not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft

Roni




-----Original Message-----

From: Eric Burger [mailto:eburger@standardstrack.com]

Sent: Thursday, July 09, 2009 11:28 PM

To: Roni Even

Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;

rai@ietf.org

Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19

 

The reality is that NO ONE has implemented any security to date. The

GENART reviewer raised the same issue, and so far the work group has

the same response: MRCPv2 (the speechsc work group) is not planning on

figuring out which of the seven key exchange mechanisms to use in

SIP.  We are counting on the community publishing something, and

people using it.  After all, we are the "using SIP for media resource

control" work group, not the "media resource control work group using

something like SIP for control."

 

Does this work for you?

 

On Jul 7, 2009, at 3:40 PM, Roni Even wrote:

 

[snip]

 

 

18.   In section 12.3 the suggestion is to use SRTP as the mandatory

interoperability mode. If the reason for mandating SRTP is for a

common mode you should also decide on a key exchange mechanism. I

suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-

not-mandatory-02

for discussion on media security.



_______________________________________________
RAI mailing list
RAI@ietf.org
https://www.ietf.org/mailman/listinfo/rai

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 





 

 

 

 

 

 


------=_NextPart_000_0A5D_01CA04DE.90AD2E80
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-webkit-nbsp-mode: space;-webkit-line-break: after-white-space'>

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Dan,<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>This is the general idea. The major reason is that there =
are
various ways to protect the data and if you are not mandating one for
interoperability then it can be more general<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>For example we have the following text when discussing =
security
in the RTP payloads specifications.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>RTP packets using the payload format defined in this
specification<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; are subject to the security considerations =
discussed in the
RTP<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; specification [RFC3550] and any appropriate =
RTP profile.&nbsp; The
main<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; security considerations for the RTP packet =
carrying the RTP
payload<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format defined within this memo are =
confidentiality,
integrity, and<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; source authenticity.&nbsp; Confidentiality =
is achieved by
encryption of<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; the RTP payload.&nbsp; Integrity of the RTP =
packets is achieved
through a<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable cryptographic integrity protection =
mechanism.&nbsp; Such
a<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; cryptographic system may also allow the =
authentication of the
source<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; of the payload.&nbsp; A suitable security =
mechanism for this RTP
payload<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format should provide confidentiality, =
integrity protection,
and at<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; least source authentication capable of =
determining if an RTP
packet<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; is from a member of the RTP =
session.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Note that the appropriate mechanism to =
provide security to
RTP and<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; payloads following this memo may vary.&nbsp; =
It is dependent on
the<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; application, the transport, and the =
signaling protocol
employed.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Therefore, a single mechanism is not =
sufficient, although if<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable, usage of the Secure Real-time =
Transport Protocol
(SRTP)<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC3711] recommended.&nbsp; Other =
mechanisms that may be used are
IPsec<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC4301] Transport Layer Security (TLS) =
[RFC5246] (RTP over
TCP);<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; other alternatives may =
exist.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Roni Even<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>
rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] <b>On Behalf Of =
</b>Dan York<br>
<b>Sent:</b> Tuesday, July 14, 2009 11:16 PM<br>
<b>To:</b> Roni Even<br>
<b>Cc:</b> 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham';
rai@ietf.org<br>
<b>Subject:</b> Re: [RAI] RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></p>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<div>

<p class=3DMsoNormal>Roni,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>The current text at&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-=
12.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12=
.3</a>
is:<o:p></o:p></p>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif"'>------</span></span><o:p></o:p></pre><pre><span=

class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>12.3. =
Media session protection&nbsp; </span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances and the output =
of text-to-speech operations. MRCPv2 servers MUST support SRTP for =
protection of audio media sessions. MRCPv2 clients that originate or =
consume audio similarly MUST support SRTP. Alternative media channel =
protection MAY be used if desired (e.g. =
IPSEC).</span></span><o:p></o:p></pre></div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Based on your comments and the srtp-not-mandatory =
draft
(which was just revised to&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">=
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a>
), my understanding would be that you are advocating something more like =
this:<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:12.0pt;
font-family:"Helvetica","sans-serif"'>12.3. Media session =
protection&nbsp;</span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:12.0pt;font-family:"Helvetica","sans-serif"'>Sensitive=
 data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></span><o:p></o:p></pre></div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Is that an accurate summary of your feedback? =
&nbsp;Would
that text be acceptable?<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Regards,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal>Dan<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<div>

<div>

<p class=3DMsoNormal>On Jul 9, 2009, at 4:56 PM, Roni Even =
wrote:<o:p></o:p></p>

</div>

<p class=3DMsoNormal><br>
<br>
<o:p></o:p></p>

<div>

<p class=3DMsoNormal>Eric,<br>
My comment is that in this case in AVT we say that you do not need =
to<br>
mandate SRTP but mandate a security mechanism that can be &nbsp;not only =
SRTP
but<br>
in a different layer like ipsec. This is why I gave a reference to =
the<br>
srtp-not-mandatory draft<br>
<br>
Roni<br>
<br>
<br>
<o:p></o:p></p>

<p class=3DMsoNormal>-----Original Message-----<o:p></o:p></p>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>From: Eric Burger [<a
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.=
com</a>]<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>Sent: Thursday, July 09, 2009 11:28 =
PM<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>To: Roni Even<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>Cc: Saravanan Shanmugham; Daniel Burnett; <a
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>Subject: Re: RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>The reality is that NO ONE has implemented any =
security to
date. The<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>GENART reviewer raised the same issue, and so far =
the work
group has<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>the same response: MRCPv2 (the speechsc work group) =
is not
planning on<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>figuring out which of the seven key exchange =
mechanisms to
use in<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>SIP. &nbsp;We are counting on the community =
publishing
something, and<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>people using it. &nbsp;After all, we are the =
&quot;using SIP
for media resource<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>control&quot; work group, not the &quot;media =
resource
control work group using<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>something like SIP for =
control.&quot;<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>Does this work for you?<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>On Jul 7, 2009, at 3:40 PM, Roni Even =
wrote:<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>[snip]<o:p></o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>18. &nbsp;&nbsp;In section 12.3 the suggestion is =
to use
SRTP as the mandatory<o:p></o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>interoperability mode. If the reason for mandating =
SRTP is
for a<o:p></o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>common mode you should also decide on a key =
exchange
mechanism. I<o:p></o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>suggest you look at<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.iet=
f.org/html/draft-ietf-avt-srtp-</a><o:p></o:p></p>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>not-mandatory-02<o:p></o:p></p>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<p class=3DMsoNormal>for discussion on media security.<o:p></o:p></p>

</blockquote>

</blockquote>

<p class=3DMsoNormal><br>
<br>
_______________________________________________<br>
RAI mailing list<br>
<a href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>
https://www.ietf.org/mailman/listinfo/rai<o:p></o:p></p>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>--&nbsp;<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Dan York, Director of Conversations<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Voxeo Corporation<span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a><o:p></o:p></span></p>=


</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Phone: +1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Join the Voxeo conversation:<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a><o:p></o:p></sp=
an></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a>
&nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a><o:p></=
o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><br>
<br>
<o:p></o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</div>

</div>

</body>

</html>

------=_NextPart_000_0A5D_01CA04DE.90AD2E80--


From dyork@voxeo.com  Tue Jul 14 14:13:02 2009
Return-Path: <dyork@voxeo.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D34293A6A3F; Tue, 14 Jul 2009 14:13:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EkrYvp774Kpa; Tue, 14 Jul 2009 14:13:00 -0700 (PDT)
Received: from voxeo.com (mmail.voxeo.com [66.193.54.208]) by core3.amsl.com (Postfix) with SMTP id BE93A3A6B50; Tue, 14 Jul 2009 14:11:06 -0700 (PDT)
Received: from [66.65.229.48] (account dyork HELO pc-00148.lodestar2.local) by voxeo.com (CommuniGate Pro SMTP 5.2.3) with ESMTPSA id 49416723; Tue, 14 Jul 2009 21:10:40 +0000
Message-Id: <F692C744-B56F-4053-BD76-4D63B61C2C48@voxeo.com>
From: Dan York <dyork@voxeo.com>
To: "Roni Even" <ron.even.tlv@gmail.com>
In-Reply-To: <4a5cf0da.190c660a.3ec0.58fa@mx.google.com>
Content-Type: multipart/alternative; boundary=Apple-Mail-147-863182515
Mime-Version: 1.0 (Apple Message framework v930.3)
Date: Tue, 14 Jul 2009 17:10:38 -0400
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>	<EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>	<05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com> <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com> <4a5cf0da.190c660a.3ec0.58fa@mx.google.com>
X-Mailer: Apple Mail (2.930.3)
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org, 'Roni Even' <Even.roni@huawei.com>
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 21:13:02 -0000

--Apple-Mail-147-863182515
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

Roni,

So as the RAI reviewer, are you okay with the text I suggested:
------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support a  
security mechanism for protection of audio media sessions. MRCPv2  
clients that originate or consume audio similarly MUST support a  
security mechanism for protection of the audio.
------

Or would you prefer this text that includes the recommendation of  
SRTP?  (Which I noticed you did in the RTP payloads spec - and it  
makes sense to me to provide some basic guidance.):
------
12.3. Media session protection
Sensitive data is also carried on media sessions terminating on MRCPv2  
servers (the other end of a media channel may or may not be on the  
MRCPv2 client). This data includes the user's spoken utterances    and  
the output of text-to-speech operations. MRCPv2 servers MUST support a  
security mechanism for protection of audio media sessions. MRCPv2  
clients that originate or consume audio similarly MUST support a  
security mechanism for protection of the audio. If appropriate, usage  
of the Secure Real-time Transport Protocol (SRTP) [RFC3711] is  
recommended.
------

Regards,
Dan

Regards,
Dan

On Jul 14, 2009, at 4:55 PM, Roni Even wrote:

> Dan,
> This is the general idea. The major reason is that there are various  
> ways to protect the data and if you are not mandating one for  
> interoperability then it can be more general
>
> For example we have the following text when discussing security in  
> the RTP payloads specifications.
>
> RTP packets using the payload format defined in this specification
>    are subject to the security considerations discussed in the RTP
>    specification [RFC3550] and any appropriate RTP profile.  The main
>    security considerations for the RTP packet carrying the RTP payload
>    format defined within this memo are confidentiality, integrity, and
>    source authenticity.  Confidentiality is achieved by encryption of
>    the RTP payload.  Integrity of the RTP packets is achieved  
> through a
>    suitable cryptographic integrity protection mechanism.  Such a
>    cryptographic system may also allow the authentication of the  
> source
>    of the payload.  A suitable security mechanism for this RTP payload
>    format should provide confidentiality, integrity protection, and at
>    least source authentication capable of determining if an RTP packet
>    is from a member of the RTP session.
>
>    Note that the appropriate mechanism to provide security to RTP and
>    payloads following this memo may vary.  It is dependent on the
>    application, the transport, and the signaling protocol employed.
>    Therefore, a single mechanism is not sufficient, although if
>    suitable, usage of the Secure Real-time Transport Protocol (SRTP)
>    [RFC3711] recommended.  Other mechanisms that may be used are IPsec
>    [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over TCP);
>    other alternatives may exist.
>
> Roni Even
>
> From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On Behalf  
> Of Dan York
> Sent: Tuesday, July 14, 2009 11:16 PM
> To: Roni Even
> Cc: 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham'; rai@ietf.org
> Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
>
> Roni,
>
> The current text at http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 
>  is:
> ------
> 12.3. Media session protection
> Sensitive data is also carried on media sessions terminating on  
> MRCPv2 servers (the other end of a media channel may or may not be  
> on the MRCPv2 client). This data includes the user's spoken  
> utterances and the output of text-to-speech operations. MRCPv2  
> servers MUST support SRTP for protection of audio media sessions.  
> MRCPv2 clients that originate or consume audio similarly MUST  
> support SRTP. Alternative media channel protection MAY be used if  
> desired (e.g. IPSEC).
> ------
>
> Based on your comments and the srtp-not-mandatory draft (which was  
> just revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03 
>  ), my understanding would be that you are advocating something more  
> like this:
>
> ------
> 12.3. Media session protection
> Sensitive data is also carried on media sessions terminating on  
> MRCPv2 servers (the other end of a media channel may or may not be  
> on the MRCPv2 client). This data includes the user's spoken  
> utterances    and the output of text-to-speech operations. MRCPv2  
> servers MUST support a security mechanism for protection of audio  
> media sessions. MRCPv2 clients that originate or consume audio  
> similarly MUST support a security mechanism for protection of the  
> audio.
> ------
>
> Is that an accurate summary of your feedback?  Would that text be  
> acceptable?
>
> Regards,
> Dan
>
> On Jul 9, 2009, at 4:56 PM, Roni Even wrote:
>
>
> Eric,
> My comment is that in this case in AVT we say that you do not need to
> mandate SRTP but mandate a security mechanism that can be  not only  
> SRTP but
> in a different layer like ipsec. This is why I gave a reference to the
> srtp-not-mandatory draft
>
> Roni
>
>
> -----Original Message-----
> From: Eric Burger [mailto:eburger@standardstrack.com]
> Sent: Thursday, July 09, 2009 11:28 PM
> To: Roni Even
> Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;
> rai@ietf.org
> Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19
>
> The reality is that NO ONE has implemented any security to date. The
> GENART reviewer raised the same issue, and so far the work group has
> the same response: MRCPv2 (the speechsc work group) is not planning on
> figuring out which of the seven key exchange mechanisms to use in
> SIP.  We are counting on the community publishing something, and
> people using it.  After all, we are the "using SIP for media resource
> control" work group, not the "media resource control work group using
> something like SIP for control."
>
> Does this work for you?
>
> On Jul 7, 2009, at 3:40 PM, Roni Even wrote:
>
> [snip]
>
>
> 18.   In section 12.3 the suggestion is to use SRTP as the mandatory
> interoperability mode. If the reason for mandating SRTP is for a
> common mode you should also decide on a key exchange mechanism. I
> suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-
> not-mandatory-02
> for discussion on media security.
>
>
> _______________________________________________
> RAI mailing list
> RAI@ietf.org
> https://www.ietf.org/mailman/listinfo/rai
>
> -- 
> Dan York, Director of Conversations
> Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com
> Phone: +1-407-455-5859    Skype: danyork
>
> Join the Voxeo conversation:
> Blogs: http://blogs.voxeo.com
> Twitter: http://twitter.com/voxeo  http://twitter.com/danyork
> Facebook: http://www.facebook.com/voxeo
>
>
>
>
>
>
>
>
>

-- 
Dan York, Director of Conversations
Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com
Phone: +1-407-455-5859    Skype: danyork

Join the Voxeo conversation:
Blogs: http://blogs.voxeo.com
Twitter: http://twitter.com/voxeo  http://twitter.com/danyork
Facebook: http://www.facebook.com/voxeo









--Apple-Mail-147-863182515
Content-Type: text/html;
	charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

<html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
-webkit-line-break: after-white-space; ">Roni,<div><br></div><div>So as =
the RAI reviewer, are you okay with the text I =
suggested:</div><div><div><div>------</div></div><div><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"font-size: 12px; white-space: =
normal;">12.3. Media session =
protection&nbsp;</span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">Sensitive data is also =
carried on media sessions terminating on MRCPv2 servers (the other end =
of a media channel may or may not be on the MRCPv2 client). This data =
includes the user's spoken utterances &nbsp; &nbsp;and the output of =
text-to-speech operations. MRCPv2 servers MUST support a security =
mechanism for protection of audio media sessions. MRCPv2 clients that =
originate or consume audio similarly MUST support a security mechanism =
for protection of the =
audio.&nbsp;</span></font></pre></div><div><div>------</div><div><br></div=
><div>Or would you prefer this text that includes the recommendation of =
SRTP? &nbsp;(Which I noticed you did in the RTP payloads spec - and it =
makes sense to me to provide some basic =
guidance.):</div><div><div><div>------</div></div><div><pre><font =
class=3D"Apple-style-span" face=3D"Helvetica" size=3D"3"><span =
class=3D"Apple-style-span" style=3D"font-size: 12px; white-space: =
normal;">12.3. Media session =
protection&nbsp;</span></font></pre><pre><font class=3D"Apple-style-span" =
face=3D"Helvetica" size=3D"3"><span class=3D"Apple-style-span" =
style=3D"font-size: 12px; white-space: normal;">Sensitive data is also =
carried on media sessions terminating on MRCPv2 servers (the other end =
of a media channel may or may not be on the MRCPv2 client). This data =
includes the user's spoken utterances &nbsp; &nbsp;and the output of =
text-to-speech operations. MRCPv2 servers MUST support a security =
mechanism for protection of audio media sessions. MRCPv2 clients that =
originate or consume audio similarly MUST support a security mechanism =
for protection of the audio. If appropriate,&nbsp;usage of the Secure =
Real-time Transport Protocol (SRTP)&nbsp;[RFC3711] is =
recommended.</span></font></pre></div><div><div>------</div><div><br></div=
><div>Regards,</div><div>Dan</div><div><br></div><div>Regards,</div><div>D=
an</div><div><br></div></div></div></div><div><div>On Jul 14, 2009, at =
4:55 PM, Roni Even wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><span =
class=3D"Apple-style-span" style=3D"border-collapse: separate; color: =
rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: =
normal; font-variant: normal; font-weight: normal; letter-spacing: =
normal; line-height: normal; orphans: 2; text-align: auto; text-indent: =
0px; text-transform: none; white-space: normal; widows: 2; word-spacing: =
0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0; "><div lang=3D"EN-US" link=3D"blue" =
vlink=3D"purple" style=3D"word-wrap: break-word; -webkit-nbsp-mode: =
space; -webkit-line-break: after-white-space; "><div =
class=3D"Section1"><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; "><span style=3D"font-size: 11pt; font-family: =
Calibri, sans-serif; color: rgb(31, 73, 125); =
">Dan,<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); ">This =
is the general idea. The major reason is that there are various ways to =
protect the data and if you are not mandating one for interoperability =
then it can be more general<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); ">For =
example we have the following text when discussing security in the RTP =
payloads specifications.<o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 11pt; font-family: Calibri, sans-serif; color: =
rgb(31, 73, 125); "><o:p>&nbsp;</o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); ">RTP packets using the payload =
format defined in this specification<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); ">&nbsp;&nbsp; are subject to the =
security considerations discussed in the RTP<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); ">&nbsp;&nbsp; specification =
[RFC3550] and any appropriate RTP profile.&nbsp; The =
main<o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; "><span style=3D"font-size: 11pt; =
font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; security considerations for the RTP packet carrying the =
RTP payload<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; format defined within this memo are confidentiality, =
integrity, and<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; source authenticity.&nbsp; Confidentiality is achieved by =
encryption of<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; the RTP payload.&nbsp; Integrity of the RTP packets is =
achieved through a<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; suitable cryptographic integrity protection =
mechanism.&nbsp; Such a<o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 11pt; font-family: Calibri, sans-serif; color: =
rgb(31, 73, 125); ">&nbsp;&nbsp; cryptographic system may also allow the =
authentication of the source<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); ">&nbsp;&nbsp; of the =
payload.&nbsp; A suitable security mechanism for this RTP =
payload<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; format should provide confidentiality, integrity =
protection, and at<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; least source authentication capable of determining if an =
RTP packet<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; is from a member of the RTP =
session.<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; Note that the appropriate mechanism to provide security =
to RTP and<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; payloads following this memo may vary.&nbsp; It is =
dependent on the<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; application, the transport, and the signaling protocol =
employed.<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; Therefore, a single mechanism is not sufficient, although =
if<o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; "><span style=3D"font-size: 11pt; =
font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; suitable, usage of the Secure Real-time Transport =
Protocol (SRTP)<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; [RFC3711] recommended.&nbsp; Other mechanisms that may be =
used are IPsec<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP =
over TCP);<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp; other alternatives may exist.<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 11pt; font-family: Calibri, =
sans-serif; color: rgb(31, 73, 125); =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><span style=3D"font-size: =
11pt; font-family: Calibri, sans-serif; color: rgb(31, 73, 125); ">Roni =
Even<o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; "><span style=3D"font-size: 11pt; =
font-family: Calibri, sans-serif; color: rgb(31, 73, 125); =
"><o:p>&nbsp;</o:p></span></div><div style=3D"border-top-style: none; =
border-right-style: none; border-bottom-style: none; border-width: =
initial; border-color: initial; border-left-style: solid; =
border-left-color: blue; border-left-width: 1.5pt; padding-top: 0in; =
padding-right: 0in; padding-bottom: 0in; padding-left: 4pt; "><div><div =
style=3D"border-right-style: none; border-bottom-style: none; =
border-left-style: none; border-width: initial; border-color: initial; =
border-top-style: solid; border-top-color: rgb(181, 196, 223); =
border-top-width: 1pt; padding-top: 3pt; padding-right: 0in; =
padding-bottom: 0in; padding-left: 0in; "><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; "><b><span =
style=3D"font-size: 10pt; font-family: Tahoma, sans-serif; =
">From:</span></b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; "><span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:rai-bounces@ietf.org">rai-bounces@ietf.org</a> [<a =
href=3D"mailto:rai-bounces@ietf.org" style=3D"color: blue; =
text-decoration: underline; ">mailto:rai-bounces@ietf.org</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Dan =
York<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, July 14, 2009 =
11:16 PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Roni =
Even<br><b>Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>'Daniel Burnett';<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org" style=3D"color: blue; text-decoration: =
underline; ">speechsc@ietf.org</a>; 'Saravanan Shanmugham';<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:rai@ietf.org" style=3D"color: blue; text-decoration: =
underline; ">rai@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [RAI] RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></div></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><o:p>&nbsp;</o:p></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
">Roni,<o:p></o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; ">The current text =
at&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-1=
2.3" style=3D"color: blue; text-decoration: underline; =
">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3</a=
><span =
class=3D"Apple-converted-space">&nbsp;</span>is:<o:p></o:p></div></div><di=
v><pre style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 10pt; font-family: 'Courier New'; =
"><span class=3D"apple-style-span"><span style=3D"font-size: 9pt; =
font-family: Helvetica, sans-serif; =
">------</span></span><o:p></o:p></pre><pre style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
10pt; font-family: 'Courier New'; "><span class=3D"apple-style-span"><span=
 style=3D"font-size: 9pt; font-family: Helvetica, sans-serif; ">12.3. =
Media session protection&nbsp; </span></span><o:p></o:p></pre><pre =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 10pt; font-family: 'Courier New'; =
"><span class=3D"apple-style-span"><span style=3D"font-size: 9pt; =
font-family: Helvetica, sans-serif; ">Sensitive data is also carried on =
media sessions terminating on MRCPv2 servers (the other end of a media =
channel may or may not be on the MRCPv2 client). This data includes the =
user's spoken utterances and the output of text-to-speech operations. =
MRCPv2 servers MUST support SRTP for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support =
SRTP. Alternative media channel protection MAY be used if desired (e.g. =
IPSEC).</span></span><o:p></o:p></pre></div><div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
">------<o:p></o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; ">Based on your comments =
and the srtp-not-mandatory draft (which was just revised to&nbsp;<a =
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03" =
style=3D"color: blue; text-decoration: underline; =
">http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a><span=
 class=3D"Apple-converted-space">&nbsp;</span>), my understanding would =
be that you are advocating something more like =
this:<o:p></o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; =
">------<o:p></o:p></div></div><div><pre style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
10pt; font-family: 'Courier New'; "><span class=3D"apple-style-span"><span=
 style=3D"font-size: 12pt; font-family: Helvetica, sans-serif; ">12.3. =
Media session protection&nbsp;</span></span><o:p></o:p></pre><pre =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 10pt; font-family: 'Courier New'; =
"><span class=3D"apple-style-span"><span style=3D"font-size: 12pt; =
font-family: Helvetica, sans-serif; ">Sensitive data is also carried on =
media sessions terminating on MRCPv2 servers (the other end of a media =
channel may or may not be on the MRCPv2 client). This data includes the =
user's spoken utterances &nbsp; &nbsp;and the output of text-to-speech =
operations. MRCPv2 servers MUST support a security mechanism for =
protection of audio media sessions. MRCPv2 clients that originate or =
consume audio similarly MUST support a security mechanism for protection =
of the audio.&nbsp;</span></span><o:p></o:p></pre></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; ">------<o:p></o:p></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><o:p>&nbsp;</o:p></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; ">Is that an accurate summary of your feedback? =
&nbsp;Would that text be acceptable?<o:p></o:p></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><o:p>&nbsp;</o:p></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; ">Regards,<o:p></o:p></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; ">Dan<o:p></o:p></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div><div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; ">On Jul 9, 2009, at 4:56 =
PM, Roni Even wrote:<o:p></o:p></div></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><br><br><o:p></o:p></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
12pt; font-family: 'Times New Roman', serif; ">Eric,<br>My comment is =
that in this case in AVT we say that you do not need to<br>mandate SRTP =
but mandate a security mechanism that can be &nbsp;not only SRTP =
but<br>in a different layer like ipsec. This is why I gave a reference =
to the<br>srtp-not-mandatory =
draft<br><br>Roni<br><br><br><o:p></o:p></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">-----Original =
Message-----<o:p></o:p></div><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">From: Eric Burger [<a =
href=3D"mailto:eburger@standardstrack.com" style=3D"color: blue; =
text-decoration: underline; =
">mailto:eburger@standardstrack.com</a>]<o:p></o:p></div></blockquote><blo=
ckquote style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; ">Sent: Thursday, July 09, 2009 11:28 =
PM<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">To: Roni =
Even<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">Cc: Saravanan Shanmugham; Daniel =
Burnett;<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org" style=3D"color: blue; text-decoration: =
underline; =
">speechsc@ietf.org</a>;<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><a =
href=3D"mailto:rai@ietf.org" style=3D"color: blue; text-decoration: =
underline; ">rai@ietf.org</a><o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">Subject: Re: =
RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; ">The reality is that NO ONE has =
implemented any security to date. =
The<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">GENART reviewer raised the same issue, and =
so far the work group has<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">the same =
response: MRCPv2 (the speechsc work group) is not planning =
on<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">figuring out which of the seven key exchange =
mechanisms to use in<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">SIP. &nbsp;We =
are counting on the community publishing something, =
and<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">people using it. &nbsp;After all, we are the =
"using SIP for media resource<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">control" work =
group, not the "media resource control work group =
using<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; ">something like SIP for =
control."<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; ">Does this work for =
you?<o:p></o:p></div></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; =
font-family: 'Times New Roman', serif; ">On Jul 7, 2009, at 3:40 PM, =
Roni Even wrote:<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote><blockquote style=3D"margin-top: =
5pt; margin-bottom: 5pt; "><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; =
">[snip]<o:p></o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">18. =
&nbsp;&nbsp;In section 12.3 the suggestion is to use SRTP as the =
mandatory<o:p></o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
">interoperability mode. If the reason for mandating SRTP is for =
a<o:p></o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">common mode =
you should also decide on a key exchange mechanism. =
I<o:p></o:p></div></blockquote></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">suggest you =
look at<a href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-" =
style=3D"color: blue; text-decoration: underline; =
">http://tools.ietf.org/html/draft-ietf-avt-srtp-</a><o:p></o:p></div></bl=
ockquote></blockquote><blockquote style=3D"margin-top: 5pt; =
margin-bottom: 5pt; "><div style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: =
'Times New Roman', serif; =
">not-mandatory-02<o:p></o:p></div></blockquote><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><blockquote =
style=3D"margin-top: 5pt; margin-bottom: 5pt; "><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; ">for discussion =
on media security.<o:p></o:p></div></blockquote></blockquote><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; =
"><br><br>_______________________________________________<br>RAI mailing =
list<br><a href=3D"mailto:RAI@ietf.org" style=3D"color: blue; =
text-decoration: underline; ">RAI@ietf.org</a><br><a =
href=3D"https://www.ietf.org/mailman/listinfo/rai" style=3D"color: blue; =
text-decoration: underline; =
">https://www.ietf.org/mailman/listinfo/rai</a><o:p></o:p></div></div></di=
v><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; =
"><o:p>&nbsp;</o:p></div><div><div><div><div><div><div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; =
">--&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 9pt; font-family: Helvetica, sans-serif; color: =
black; ">Dan York, Director of =
Conversations<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 9pt; font-family: Helvetica, sans-serif; color: =
black; ">Voxeo Corporation<span =
class=3D"apple-converted-space">&nbsp;</span>&nbsp;&nbsp;<a =
href=3D"http://www.voxeo.com" style=3D"color: blue; text-decoration: =
underline; ">http://www.voxeo.com</a>&nbsp;<span =
class=3D"apple-converted-space">&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com" style=3D"color: blue; text-decoration: =
underline; ">dyork@voxeo.com</a><o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; ">Phone: +1-407-455-5859&nbsp;<span =
class=3D"apple-converted-space">&nbsp;&nbsp;&nbsp;</span>Skype: =
danyork&nbsp;<span =
class=3D"apple-converted-space">&nbsp;</span><o:p></o:p></span></div></div=
><div><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; =
"><o:p>&nbsp;</o:p></span></div></div><div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 9pt; font-family: Helvetica, sans-serif; color: =
black; ">Join the Voxeo =
conversation:<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; "><span =
style=3D"font-size: 9pt; font-family: Helvetica, sans-serif; color: =
black; ">Blogs:<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://blogs.voxeo.com" style=3D"color: blue; text-decoration: =
underline; =
">http://blogs.voxeo.com</a><o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; ">Twitter:<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://twitter.com/voxeo" style=3D"color: blue; text-decoration: =
underline; ">http://twitter.com/voxeo</a><span =
class=3D"Apple-converted-space">&nbsp;</span>&nbsp;<a =
href=3D"http://twitter.com/danyork" style=3D"color: blue; =
text-decoration: underline; =
">http://twitter.com/danyork</a><o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; ">Facebook:<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://www.facebook.com/voxeo" style=3D"color: blue; =
text-decoration: underline; =
">http://www.facebook.com/voxeo</a><o:p></o:p></span></div></div></div><di=
v><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><o:p>&nbsp;</o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><br><br><o:p></o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><o:p>&nbsp;</o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><o:p>&nbsp;</o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><o:p>&nbsp;</o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><span style=3D"font-size: 9pt; font-family: Helvetica, =
sans-serif; color: black; "><o:p>&nbsp;</o:p></span></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 12pt; font-family: 'Times New =
Roman', serif; "><o:p>&nbsp;</o:p></div></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 12pt; font-family: 'Times New Roman', serif; =
"><o:p>&nbsp;</o:p></div></div></div></div></div></span></blockquote></div=
><br><div apple-content-edited=3D"true"> <span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; -webkit-border-horizontal-spacing: =
0px; -webkit-border-vertical-spacing: 0px; color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; -webkit-text-decorations-in-effect: none; =
text-indent: 0px; -webkit-text-size-adjust: auto; text-transform: none; =
orphans: 2; white-space: normal; widows: 2; word-spacing: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">--&nbsp;</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Dan York, =
Director of Conversations</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">Voxeo =
Corporation<span =
class=3D"Apple-converted-space">&nbsp;</span>&nbsp;&nbsp;<a =
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Phone: +1-407-455-5859&nbsp;<span =
class=3D"Apple-converted-space">&nbsp;&nbsp;&nbsp;</span>Skype: =
danyork&nbsp;<span class=3D"Apple-converted-space">&nbsp;</span></div><div=
 style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Join the Voxeo conversation:</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; ">Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a> &nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></div><d=
iv style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 12px/normal Helvetica; =
min-height: 14px; ">Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a></=
div></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
12px/normal Helvetica; min-height: 14px; "><br =
class=3D"khtml-block-placeholder"></div><br =
class=3D"Apple-interchange-newline"></span></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"> </div><br></div></body></html>=

--Apple-Mail-147-863182515--

From ron.even.tlv@gmail.com  Tue Jul 14 15:01:43 2009
Return-Path: <ron.even.tlv@gmail.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7DA2F3A635F; Tue, 14 Jul 2009 15:01:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.165
X-Spam-Level: 
X-Spam-Status: No, score=-2.165 tagged_above=-999 required=5 tests=[AWL=0.433,  BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mdfQN+LUIwT3; Tue, 14 Jul 2009 15:01:41 -0700 (PDT)
Received: from mail-fx0-f218.google.com (mail-fx0-f218.google.com [209.85.220.218]) by core3.amsl.com (Postfix) with ESMTP id A6F433A6E60; Tue, 14 Jul 2009 15:01:24 -0700 (PDT)
Received: by fxm18 with SMTP id 18so3101102fxm.37 for <multiple recipients>; Tue, 14 Jul 2009 15:00:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:from:to:cc:references :in-reply-to:subject:date:message-id:mime-version:content-type :x-mailer:thread-index:content-language; bh=jKIvUZ2UzofS+UNKUoF/lXaPGvA3D8jZA8LscnDzTUI=; b=a0hN5icK67E/9U7kdht3MmSc2ZNYXfMRUzg/4oXhib0JpwSio3gwQOPg70Kf/5s8H5 YhX9CvijbG7ZNGHMXvFbPX7OzOHplal2wgfudMGArU5oRorX6Az4m1wDXOioTt1s/ArA kS3UNvsSO6tj60ges99fhz2lBp4fKJDx1gnz8=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=from:to:cc:references:in-reply-to:subject:date:message-id :mime-version:content-type:x-mailer:thread-index:content-language; b=GVe0Eanxh9srxlnumxNB/mwvqUlNoZNK1pqnFPbhG2avak2ZqIc4ghzH8pFAQZG2ZI znEJ2Zw+WUVyI7uNeffnNAPFd4uDgEK2LMrzw0zGN/wa8YjDdTb1lKuDNsLWT1Tbr40g 2pyOOffHG2j7zXzLpRe09+rJ5FsPehXdp+JsU=
Received: by 10.103.131.13 with SMTP id i13mr3715652mun.64.1247607397188; Tue, 14 Jul 2009 14:36:37 -0700 (PDT)
Received: from windows8d787f9 (bzq-79-179-66-37.red.bezeqint.net [79.179.66.37]) by mx.google.com with ESMTPS id n10sm30032606mue.17.2009.07.14.14.36.34 (version=TLSv1/SSLv3 cipher=RC4-MD5); Tue, 14 Jul 2009 14:36:36 -0700 (PDT)
From: "Roni Even" <ron.even.tlv@gmail.com>
To: "'Dan York'" <dyork@voxeo.com>
References: <033101c9ff3a$cbe33160$63a99420$%roni@huawei.com>	<EE02487B-63DE-4CC6-81A9-7A4FAAD4A76D@standardstrack.com>	<05e101ca00d7$bc996aa0$35cc3fe0$%roni@huawei.com> <53ADC9B8-F9D2-4B27-A6D8-96B507911343@voxeo.com> <4a5cf0da.190c660a.3ec0.58fa@mx.google.com> <F692C744-B56F-4053-BD76-4D63B61C2C48@voxeo.com>
In-Reply-To: <F692C744-B56F-4053-BD76-4D63B61C2C48@voxeo.com>
Date: Wed, 15 Jul 2009 00:36:08 +0300
Message-ID: <4a5cfa64.0aa5660a.1918.ffff94d6@mx.google.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0A87_01CA04E4.4014F3D0"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcoEx4wp7NhipJKURgG7lWCJ5mWaSgAAykQQ
Content-Language: en-us
X-Mailman-Approved-At: Wed, 15 Jul 2009 08:14:53 -0700
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org, 'Roni Even' <Even.roni@huawei.com>
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 22:01:43 -0000

This is a multi-part message in MIME format.

------=_NextPart_000_0A87_01CA04E4.4014F3D0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Dan,

I prefer the text that recommends SRTP (It is a SHOULD and not a MUST). The
text we currently have is based on the security reviews we got for RTP
payload specifications, and as you can see it addresses the issue of why not
to mandate SRTP.

Roni

 

From: Dan York [mailto:dyork@voxeo.com] 
Sent: Wednesday, July 15, 2009 12:11 AM
To: Roni Even
Cc: 'Roni Even'; 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan
Shanmugham'; rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

So as the RAI reviewer, are you okay with the text I suggested:

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Or would you prefer this text that includes the recommendation of SRTP?
(Which I noticed you did in the RTP payloads spec - and it makes sense to me
to provide some basic guidance.):

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. If appropriate, usage of the Secure Real-time
Transport Protocol (SRTP) [RFC3711] is recommended.

------

 

Regards,

Dan

 

Regards,

Dan

 

On Jul 14, 2009, at 4:55 PM, Roni Even wrote:





Dan,

This is the general idea. The major reason is that there are various ways to
protect the data and if you are not mandating one for interoperability then
it can be more general

 

For example we have the following text when discussing security in the RTP
payloads specifications.

 

RTP packets using the payload format defined in this specification

   are subject to the security considerations discussed in the RTP

   specification [RFC3550] and any appropriate RTP profile.  The main

   security considerations for the RTP packet carrying the RTP payload

   format defined within this memo are confidentiality, integrity, and

   source authenticity.  Confidentiality is achieved by encryption of

   the RTP payload.  Integrity of the RTP packets is achieved through a

   suitable cryptographic integrity protection mechanism.  Such a

   cryptographic system may also allow the authentication of the source

   of the payload.  A suitable security mechanism for this RTP payload

   format should provide confidentiality, integrity protection, and at

   least source authentication capable of determining if an RTP packet

   is from a member of the RTP session.

 

   Note that the appropriate mechanism to provide security to RTP and

   payloads following this memo may vary.  It is dependent on the

   application, the transport, and the signaling protocol employed.

   Therefore, a single mechanism is not sufficient, although if

   suitable, usage of the Secure Real-time Transport Protocol (SRTP)

   [RFC3711] recommended.  Other mechanisms that may be used are IPsec

   [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over TCP);

   other alternatives may exist.

 

Roni Even

 

From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On Behalf Of Dan
York
Sent: Tuesday, July 14, 2009 11:16 PM
To: Roni Even
Cc: 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham';
rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

The current text at
http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 is:

------
12.3. Media session protection  
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances and the output of
text-to-speech operations. MRCPv2 servers MUST support SRTP for protection
of audio media sessions. MRCPv2 clients that originate or consume audio
similarly MUST support SRTP. Alternative media channel protection MAY be
used if desired (e.g. IPSEC).

------

 

Based on your comments and the srtp-not-mandatory draft (which was just
revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03
), my understanding would be that you are advocating something more like
this:

 

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Is that an accurate summary of your feedback?  Would that text be
acceptable?

 

Regards,

Dan

 

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:






Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be  not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft

Roni





-----Original Message-----

From: Eric Burger [mailto:eburger@standardstrack.com]

Sent: Thursday, July 09, 2009 11:28 PM

To: Roni Even

Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;

rai@ietf.org

Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19

 

The reality is that NO ONE has implemented any security to date. The

GENART reviewer raised the same issue, and so far the work group has

the same response: MRCPv2 (the speechsc work group) is not planning on

figuring out which of the seven key exchange mechanisms to use in

SIP.  We are counting on the community publishing something, and

people using it.  After all, we are the "using SIP for media resource

control" work group, not the "media resource control work group using

something like SIP for control."

 

Does this work for you?

 

On Jul 7, 2009, at 3:40 PM, Roni Even wrote:

 

[snip]

 

 

18.   In section 12.3 the suggestion is to use SRTP as the mandatory

interoperability mode. If the reason for mandating SRTP is for a

common mode you should also decide on a key exchange mechanism. I

suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-

not-mandatory-02

for discussion on media security.



_______________________________________________
RAI mailing list
RAI@ietf.org
https://www.ietf.org/mailman/listinfo/rai

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 






 

 

 

 

 

 

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 





 

 

 

 

 

 


------=_NextPart_000_0A87_01CA04E4.4014F3D0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-webkit-nbsp-mode: space;-webkit-line-break: after-white-space'>

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Dan,<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I prefer the text that recommends SRTP (It is a SHOULD =
and not a
MUST). The text we currently have is based on the security reviews we =
got for
RTP payload specifications, and as you can see it addresses the issue of =
why
not to mandate SRTP.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Roni<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> Dan York
[mailto:dyork@voxeo.com] <br>
<b>Sent:</b> Wednesday, July 15, 2009 12:11 AM<br>
<b>To:</b> Roni Even<br>
<b>Cc:</b> 'Roni Even'; 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan
Shanmugham'; rai@ietf.org<br>
<b>Subject:</b> Re: [RAI] RAI review of =
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></p>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal>Roni,<o:p></o:p></p>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>So as the RAI reviewer, are you okay with the text =
I
suggested:<o:p></o:p></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif"'>12.3. Media session =
protection&nbsp;</span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Or would you prefer this text that includes the
recommendation of SRTP? &nbsp;(Which I noticed you did in the RTP =
payloads spec
- and it makes sense to me to provide some basic =
guidance.):<o:p></o:p></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif"'>12.3. Media session =
protection&nbsp;</span></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif"'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the audio. If =
appropriate,&nbsp;usage of the Secure Real-time Transport Protocol =
(SRTP)&nbsp;[RFC3711] is =
recommended.</span></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal>------<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Regards,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal>Dan<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<div>

<p class=3DMsoNormal>Regards,<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal>Dan<o:p></o:p></p>

</div>

<div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal>On Jul 14, 2009, at 4:55 PM, Roni Even =
wrote:<o:p></o:p></p>

</div>

<p class=3DMsoNormal><br>
<br>
<o:p></o:p></p>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Dan,</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>This is the general idea. The major reason is that there =
are
various ways to protect the data and if you are not mandating one for
interoperability then it can be more general</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>For example we have the following text when discussing =
security
in the RTP payloads specifications.</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>RTP packets using the payload format defined in this
specification</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; are subject to the security considerations
discussed in the RTP</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; specification [RFC3550] and any appropriate =
RTP
profile.&nbsp; The main</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; security considerations for the RTP packet =
carrying
the RTP payload</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format defined within this memo are
confidentiality, integrity, and</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; source authenticity.&nbsp; Confidentiality =
is
achieved by encryption of</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; the RTP payload.&nbsp; Integrity of the RTP =
packets
is achieved through a</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable cryptographic integrity protection
mechanism.&nbsp; Such a</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; cryptographic system may also allow the
authentication of the source</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; of the payload.&nbsp; A suitable security =
mechanism
for this RTP payload</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; format should provide confidentiality, =
integrity
protection, and at</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; least source authentication capable of =
determining
if an RTP packet</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; is from a member of the RTP =
session.</span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Note that the appropriate mechanism to =
provide
security to RTP and</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; payloads following this memo may vary.&nbsp; =
It is dependent
on the</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; application, the transport, and the =
signaling
protocol employed.</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; Therefore, a single mechanism is not =
sufficient,
although if</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; suitable, usage of the Secure Real-time =
Transport
Protocol (SRTP)</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC3711] recommended.&nbsp; Other =
mechanisms that
may be used are IPsec</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; [RFC4301] Transport Layer Security (TLS) =
[RFC5246]
(RTP over TCP);</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;&nbsp; other alternatives may exist.</span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Roni Even</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt;
border-width:initial;border-color:initial'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in;
border-width:initial;border-color:initial'>

<div>

<p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";
color:black'>From:</span></b><span class=3Dapple-converted-space><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a
href=3D"mailto:rai-bounces@ietf.org">rai-bounces@ietf.org</a> [<a
href=3D"mailto:rai-bounces@ietf.org">mailto:rai-bounces@ietf.org</a>]<spa=
n
class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span
class=3Dapple-converted-space>&nbsp;</span></b>Dan York<br>
<b>Sent:</b><span class=3Dapple-converted-space>&nbsp;</span>Tuesday, =
July 14,
2009 11:16 PM<br>
<b>To:</b><span class=3Dapple-converted-space>&nbsp;</span>Roni Even<br>
<b>Cc:</b><span class=3Dapple-converted-space>&nbsp;</span>'Daniel =
Burnett';<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;
'Saravanan Shanmugham';<span =
class=3Dapple-converted-space>&nbsp;</span><a
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><br>
<b>Subject:</b><span class=3Dapple-converted-space>&nbsp;</span>Re: =
[RAI] RAI
review of draft-ietf-speechsc-mrcpv2-19</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Roni,<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>The current text =
at&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-=
12.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12=
.3</a><span
class=3Dapple-converted-space>&nbsp;</span>is:<o:p></o:p></span></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:9.0pt;font-family:
"Helvetica","sans-serif";color:black'>------</span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";color:black=
'>12.3. Media session protection&nbsp; </span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";color:black=
'>Sensitive data is also carried on media sessions terminating on MRCPv2 =
servers (the other end of a media channel may or may not be on the =
MRCPv2 client). This data includes the user's spoken utterances and the =
output of text-to-speech operations. MRCPv2 servers MUST support SRTP =
for protection of audio media sessions. MRCPv2 clients that originate or =
consume audio similarly MUST support SRTP. Alternative media channel =
protection MAY be used if desired (e.g. IPSEC).</span></span><span
style=3D'color:black'><o:p></o:p></span></pre></div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Based on your comments =
and the
srtp-not-mandatory draft (which was just revised to&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">=
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a><span
class=3Dapple-converted-space>&nbsp;</span>), my understanding would be =
that you
are advocating something more like this:<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><span =
style=3D'font-size:12.0pt;
font-family:"Helvetica","sans-serif";color:black'>12.3. Media session =
protection&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></pre><pre><span =
class=3Dapple-style-span><span
style=3D'font-size:12.0pt;font-family:"Helvetica","sans-serif";color:blac=
k'>Sensitive data is also carried on media sessions terminating on =
MRCPv2 servers (the other end of a media channel may or may not be on =
the MRCPv2 client). This data includes the user's spoken utterances =
&nbsp; &nbsp;and the output of text-to-speech operations. MRCPv2 servers =
MUST support a security mechanism for protection of audio media =
sessions. MRCPv2 clients that originate or consume audio similarly MUST =
support a security mechanism for protection of the =
audio.&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></pre></div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>------<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Is that an accurate =
summary of
your feedback? &nbsp;Would that text be =
acceptable?<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Regards,<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>Dan<o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>On Jul 9, 2009, at 4:56 =
PM, Roni
Even wrote:<o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><br>
<br>
<br>
<o:p></o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Eric,<br>
My comment is that in this case in AVT we say that you do not need =
to<br>
mandate SRTP but mandate a security mechanism that can be &nbsp;not only =
SRTP
but<br>
in a different layer like ipsec. This is why I gave a reference to =
the<br>
srtp-not-mandatory draft<br>
<br>
Roni<br>
<br>
<br>
<br>
<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>-----Original =
Message-----<o:p></o:p></span></p>

</div>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>From: Eric Burger [<a
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.=
com</a>]<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Sent: Thursday, July =
09, 2009
11:28 PM<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>To: Roni =
Even<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Cc: Saravanan =
Shanmugham; Daniel
Burnett;<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<o:p></o:p></span=
></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Subject: Re: RAI review =
of
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>The reality is that NO =
ONE has
implemented any security to date. The<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>GENART reviewer raised =
the same
issue, and so far the work group has<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>the same response: =
MRCPv2 (the
speechsc work group) is not planning on<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>figuring out which of =
the seven
key exchange mechanisms to use in<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>SIP. &nbsp;We are =
counting on the
community publishing something, and<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>people using it. =
&nbsp;After all,
we are the &quot;using SIP for media resource<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>control&quot; work =
group, not the
&quot;media resource control work group using<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>something like SIP for =
control.&quot;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>Does this work for =
you?<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>On Jul 7, 2009, at 3:40 =
PM, Roni
Even wrote:<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>[snip]<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>18. &nbsp;&nbsp;In =
section 12.3
the suggestion is to use SRTP as the mandatory<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>interoperability mode. =
If the
reason for mandating SRTP is for a<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>common mode you should =
also decide
on a key exchange mechanism. I<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>suggest you look at<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.iet=
f.org/html/draft-ietf-avt-srtp-</a><o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>not-mandatory-02<o:p></o:p></span></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><span style=3D'color:black'>for discussion on media =
security.<o:p></o:p></span></p>

</div>

</blockquote>

</blockquote>

<div>

<p class=3DMsoNormal><span style=3D'color:black'><br>
<br>
_______________________________________________<br>
RAI mailing list<br>
<a href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>
<a =
href=3D"https://www.ietf.org/mailman/listinfo/rai">https://www.ietf.org/m=
ailman/listinfo/rai</a><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>--&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Dan York, Director of Conversations</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Voxeo Corporation<span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Phone: +1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Join the Voxeo conversation:</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Blogs:<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Twitter:<span class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a><span
class=3Dapple-converted-space>&nbsp;</span>&nbsp;<a
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></span>=
<span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Facebook:<span =
class=3Dapple-converted-space>&nbsp;</span><a
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
/span><span
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><br>
<br>
<br>
</span><span style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p>

</div>

</div>

</div>

</div>

</div>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>--&nbsp;<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Dan York, Director of Conversations<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Voxeo Corporation<span =
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a><o:p></o:p></span></p>=


</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Phone: +1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Join the Voxeo conversation:<o:p></o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Blogs: <a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a><o:p></o:p></sp=
an></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Twitter: <a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a>
&nbsp;<a =
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a><o:p></=
o:p></span></p>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'>Facebook: <a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
o:p></o:p></span></p>

</div>

</div>

<div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><br>
<br>
<o:p></o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Helvetica","sans-serif";
color:black'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</div>

</div>

</body>

</html>

------=_NextPart_000_0A87_01CA04E4.4014F3D0--


From judith@jmarkowitz.com  Wed Jul 15 10:30:27 2009
Return-Path: <judith@jmarkowitz.com>
X-Original-To: speechsc@core3.amsl.com
Delivered-To: speechsc@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D1E063A683A for <speechsc@core3.amsl.com>; Wed, 15 Jul 2009 10:30:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.795
X-Spam-Level: 
X-Spam-Status: No, score=-1.795 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.803]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b-M8p5mgaD6e for <speechsc@core3.amsl.com>; Wed, 15 Jul 2009 10:30:27 -0700 (PDT)
Received: from omr7.networksolutionsemail.com (omr7.networksolutionsemail.com [205.178.146.57]) by core3.amsl.com (Postfix) with ESMTP id DDD273A6BF8 for <speechsc@ietf.org>; Wed, 15 Jul 2009 10:30:25 -0700 (PDT)
Received: from mail.networksolutionsemail.com (ns-omr7.mgt.netsol.com [10.49.6.70]) by omr7.networksolutionsemail.com (8.13.6/8.13.6) with SMTP id n6FHTMcE013222 for <speechsc@ietf.org>; Wed, 15 Jul 2009 13:29:24 -0400
Message-Id: <200907151729.n6FHTMcE013222@omr7.networksolutionsemail.com>
Received: (qmail 25960 invoked by uid 78); 15 Jul 2009 17:29:21 -0000
Received: from unknown (HELO JMarkowitz) (judith@jmarkowitz.com@24.148.52.60) by ns-omr7.lb.hosting.dc2.netsol.com with SMTP; 15 Jul 2009 17:29:21 -0000
From: "Judith Markowitz" <judith@jmarkowitz.com>
To: "'Roni Even'" <ron.even.tlv@gmail.com>, "'Dan York'" <dyork@voxeo.com>
Date: Wed, 15 Jul 2009 12:28:25 -0500
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_002C_01CA0547.C0955730"
X-Mailer: Microsoft Office Outlook, Build 11.0.6353
Thread-Index: AcoEx4wp7NhipJKURgG7lWCJ5mWaSgAAykQQACmXH9A=
In-Reply-To: <4a5cfa64.0aa5660a.1918.ffff94d6@mx.google.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
Cc: speechsc@ietf.org, 'Saravanan Shanmugham' <sarvi@cisco.com>, rai@ietf.org, 'Roni Even' <Even.roni@huawei.com>
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19
X-BeenThere: speechsc@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Speech Services Control Working Group <speechsc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/speechsc>
List-Post: <mailto:speechsc@ietf.org>
List-Help: <mailto:speechsc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/speechsc>, <mailto:speechsc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Jul 2009 17:30:27 -0000

This is a multi-part message in MIME format.

------=_NextPart_000_002C_01CA0547.C0955730
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

I want to support the position of recommending but not mandating. The
approach used needs to comply with the policies and procedures of an
organization. 

It could very well be that those policies and procedures are far more
stringent than anything that would be mandated by MRCP V2. So, if a
particular approach 

or  technology is mandated the use of MRCP may be rejected because the
security is not adequate or proper. 

 

Judith Markowitz

 

J. Markowitz, Consultants

5801 N. Sheridan Rd, #19A

Chicago, IL 60660

773-769-9243

judith@jmarkowitz.com

 

 

  _____  

From: speechsc-bounces@ietf.org [mailto:speechsc-bounces@ietf.org] On Behalf
Of Roni Even
Sent: Tuesday, July 14, 2009 4:36 PM
To: 'Dan York'
Cc: speechsc@ietf.org; 'Saravanan Shanmugham'; rai@ietf.org; 'Roni Even'
Subject: Re: [Speechsc] [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Dan,

I prefer the text that recommends SRTP (It is a SHOULD and not a MUST). The
text we currently have is based on the security reviews we got for RTP
payload specifications, and as you can see it addresses the issue of why not
to mandate SRTP.

Roni

 

From: Dan York [mailto:dyork@voxeo.com] 
Sent: Wednesday, July 15, 2009 12:11 AM
To: Roni Even
Cc: 'Roni Even'; 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan
Shanmugham'; rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

So as the RAI reviewer, are you okay with the text I suggested:

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Or would you prefer this text that includes the recommendation of SRTP?
(Which I noticed you did in the RTP payloads spec - and it makes sense to me
to provide some basic guidance.):

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. If appropriate, usage of the Secure Real-time
Transport Protocol (SRTP) [RFC3711] is recommended.

------

 

Regards,

Dan

 

Regards,

Dan

 

On Jul 14, 2009, at 4:55 PM, Roni Even wrote:

 

Dan,

This is the general idea. The major reason is that there are various ways to
protect the data and if you are not mandating one for interoperability then
it can be more general

 

For example we have the following text when discussing security in the RTP
payloads specifications.

 

RTP packets using the payload format defined in this specification

   are subject to the security considerations discussed in the RTP

   specification [RFC3550] and any appropriate RTP profile.  The main

   security considerations for the RTP packet carrying the RTP payload

   format defined within this memo are confidentiality, integrity, and

   source authenticity.  Confidentiality is achieved by encryption of

   the RTP payload.  Integrity of the RTP packets is achieved through a

   suitable cryptographic integrity protection mechanism.  Such a

   cryptographic system may also allow the authentication of the source

   of the payload.  A suitable security mechanism for this RTP payload

   format should provide confidentiality, integrity protection, and at

   least source authentication capable of determining if an RTP packet

   is from a member of the RTP session.

 

   Note that the appropriate mechanism to provide security to RTP and

   payloads following this memo may vary.  It is dependent on the

   application, the transport, and the signaling protocol employed.

   Therefore, a single mechanism is not sufficient, although if

   suitable, usage of the Secure Real-time Transport Protocol (SRTP)

   [RFC3711] recommended.  Other mechanisms that may be used are IPsec

   [RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over TCP);

   other alternatives may exist.

 

Roni Even

 

From: rai-bounces@ietf.org [mailto:rai-bounces@ietf.org] On Behalf Of Dan
York
Sent: Tuesday, July 14, 2009 11:16 PM
To: Roni Even
Cc: 'Daniel Burnett'; speechsc@ietf.org; 'Saravanan Shanmugham';
rai@ietf.org
Subject: Re: [RAI] RAI review of draft-ietf-speechsc-mrcpv2-19

 

Roni,

 

The current text at
http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12.3 is:

------
12.3. Media session protection  
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances and the output of
text-to-speech operations. MRCPv2 servers MUST support SRTP for protection
of audio media sessions. MRCPv2 clients that originate or consume audio
similarly MUST support SRTP. Alternative media channel protection MAY be
used if desired (e.g. IPSEC).

------

 

Based on your comments and the srtp-not-mandatory draft (which was just
revised to http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03
), my understanding would be that you are advocating something more like
this:

 

------

12.3. Media session protection 
Sensitive data is also carried on media sessions terminating on MRCPv2
servers (the other end of a media channel may or may not be on the MRCPv2
client). This data includes the user's spoken utterances    and the output
of text-to-speech operations. MRCPv2 servers MUST support a security
mechanism for protection of audio media sessions. MRCPv2 clients that
originate or consume audio similarly MUST support a security mechanism for
protection of the audio. 

------

 

Is that an accurate summary of your feedback?  Would that text be
acceptable?

 

Regards,

Dan

 

On Jul 9, 2009, at 4:56 PM, Roni Even wrote:





Eric,
My comment is that in this case in AVT we say that you do not need to
mandate SRTP but mandate a security mechanism that can be  not only SRTP but
in a different layer like ipsec. This is why I gave a reference to the
srtp-not-mandatory draft

Roni




-----Original Message-----

From: Eric Burger [mailto:eburger@standardstrack.com]

Sent: Thursday, July 09, 2009 11:28 PM

To: Roni Even

Cc: Saravanan Shanmugham; Daniel Burnett; speechsc@ietf.org;

rai@ietf.org

Subject: Re: RAI review of draft-ietf-speechsc-mrcpv2-19

 

The reality is that NO ONE has implemented any security to date. The

GENART reviewer raised the same issue, and so far the work group has

the same response: MRCPv2 (the speechsc work group) is not planning on

figuring out which of the seven key exchange mechanisms to use in

SIP.  We are counting on the community publishing something, and

people using it.  After all, we are the "using SIP for media resource

control" work group, not the "media resource control work group using

something like SIP for control."

 

Does this work for you?

 

On Jul 7, 2009, at 3:40 PM, Roni Even wrote:

 

[snip]

 

 

18.   In section 12.3 the suggestion is to use SRTP as the mandatory

interoperability mode. If the reason for mandating SRTP is for a

common mode you should also decide on a key exchange mechanism. I

suggest you look athttp://tools.ietf.org/html/draft-ietf-avt-srtp-

not-mandatory-02

for discussion on media security.



_______________________________________________
RAI mailing list
RAI@ietf.org
https://www.ietf.org/mailman/listinfo/rai

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 





 

 

 

 

 

 

 

-- 

Dan York, Director of Conversations

Voxeo Corporation   http://www.voxeo.com  dyork@voxeo.com

Phone: +1-407-455-5859    Skype: danyork  

 

Join the Voxeo conversation:

Blogs: http://blogs.voxeo.com

Twitter: http://twitter.com/voxeo  http://twitter.com/danyork

Facebook: http://www.facebook.com/voxeo

 

 

 

 

 

 

 

 


------=_NextPart_000_002C_01CA0547.C0955730
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40"
xmlns:ns1=3D"http://schemas.microsoft.com/office/2004/12/omml">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--a:link
	{mso-style-priority:99;}
span.MSOHYPERLINK
	{mso-style-priority:99;}
a:visited
	{mso-style-priority:99;}
span.MSOHYPERLINKFOLLOWED
	{mso-style-priority:99;}
pre
	{mso-style-priority:99;}
span.HTMLPREFORMATTEDCHAR
	{mso-style-priority:99;}

 /* Font Definitions */
 @font-face
	{font-family:Helvetica;
	panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Calibri;}
@font-face
	{font-family:Consolas;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline;}
pre
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
p.MonitoringReport, li.MonitoringReport, div.MonitoringReport
	{margin:0in;
	margin-bottom:.0001pt;
	text-align:justify;
	background:white;
	font-size:10.0pt;
	font-family:Arial;}
p.monitoringreport0, li.monitoringreport0, div.monitoringreport0
	{margin:0in;
	margin-bottom:.0001pt;
	text-align:justify;
	font-size:10.0pt;
	font-family:Arial;
	font-weight:bold;}
p.Monitoringreport1, li.Monitoringreport1, div.Monitoringreport1
	{margin:0in;
	margin-bottom:.0001pt;
	text-align:justify;
	font-size:10.0pt;
	font-family:Arial;}
span.HTMLPreformattedChar
	{font-family:Consolas;}
span.EmailStyle24
	{mso-style-type:personal;
	font-family:Calibri;
	color:#1F497D;}
span.EmailStyle25
	{mso-style-type:personal-reply;
	font-family:Arial;
	color:blue;
	font-weight:normal;
	font-style:normal;
	text-decoration:none none;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'word-wrap: =
break-word;
-webkit-nbsp-mode: space;-webkit-line-break: after-white-space'>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'>I want to support the position of
recommending but not mandating. The approach used needs to comply with =
the
policies and procedures of an organization. =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'>It could very well be that those =
policies
and procedures are far more stringent than anything that would be =
mandated by
MRCP V2. So, if a particular approach <o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'>or &nbsp;technology is mandated the =
use of
MRCP may be rejected because the security is not adequate or proper. =
<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'>Judith =
Markowitz<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>J. Markowitz, =
Consultants</span></font><o:p></o:p></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>5801 N. Sheridan Rd, =
#19A</span></font><o:p></o:p></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>Chicago, IL 60660</span></font><o:p></o:p></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>773-769-9243</span></font><o:p></o:p></p>

<p class=3DMsoNormal><font size=3D2 face=3DArial><span =
style=3D'font-size:10.0pt;
font-family:Arial'>judith@jmarkowitz.com</span></font><o:p></o:p></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dblue face=3DArial><span =
style=3D'font-size:
11.0pt;font-family:Arial;color:blue'><o:p>&nbsp;</o:p></span></font></p>

<div>

<div class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><font =
size=3D3
face=3D"Times New Roman"><span style=3D'font-size:12.0pt'>

<hr size=3D2 width=3D"100%" align=3Dcenter tabindex=3D-1>

</span></font></div>

<p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span =
style=3D'font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font =
size=3D2
face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'>
speechsc-bounces@ietf.org [mailto:speechsc-bounces@ietf.org] <b><span
style=3D'font-weight:bold'>On Behalf Of </span></b>Roni Even<br>
<b><span style=3D'font-weight:bold'>Sent:</span></b> Tuesday, July 14, =
2009 4:36
PM<br>
<b><span style=3D'font-weight:bold'>To:</span></b> 'Dan York'<br>
<b><span style=3D'font-weight:bold'>Cc:</span></b> speechsc@ietf.org; =
'Saravanan
Shanmugham'; rai@ietf.org; 'Roni Even'<br>
<b><span style=3D'font-weight:bold'>Subject:</span></b> Re: [Speechsc] =
[RAI] RAI
review of draft-ietf-speechsc-mrcpv2-19</span></font><o:p></o:p></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>Dan,<o:p></o=
:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>I prefer =
the text
that recommends SRTP (It is a SHOULD and not a MUST). The text we =
currently have
is based on the security reviews we got for RTP payload specifications, =
and as
you can see it addresses the issue of why not to mandate =
SRTP.<o:p></o:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>Roni<o:p></o=
:p></span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'><o:p>&nbsp;<=
/o:p></span></font></p>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal><b><font size=3D2 face=3DTahoma><span =
style=3D'font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font =
size=3D2
face=3DTahoma><span style=3D'font-size:10.0pt;font-family:Tahoma'> Dan =
York
[mailto:dyork@voxeo.com] <br>
<b><span style=3D'font-weight:bold'>Sent:</span></b> Wednesday, July 15, =
2009
12:11 AM<br>
<b><span style=3D'font-weight:bold'>To:</span></b> Roni Even<br>
<b><span style=3D'font-weight:bold'>Cc:</span></b> 'Roni Even'; 'Daniel =
Burnett';
speechsc@ietf.org; 'Saravanan Shanmugham'; rai@ietf.org<br>
<b><span style=3D'font-weight:bold'>Subject:</span></b> Re: [RAI] RAI =
review of
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></font></p>

</div>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Roni,<o:p></o:p></span></font></p>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>So as the RAI reviewer, are you okay with the text I =
suggested:<o:p></o:p></span></font></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>------<o:p></o:p></span></font></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><font size=3D1 =
face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica'>12.3. Media session =
protection&nbsp;</span></font></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><font size=3D1 face=3DHelvetica><span =
style=3D'font-size:9.0pt;
font-family:Helvetica'>Sensitive data is also carried on media sessions =
terminating on MRCPv2 servers (the other end of a media channel may or =
may not be on the MRCPv2 client). This data includes the user's spoken =
utterances &nbsp; &nbsp;and the output of text-to-speech operations. =
MRCPv2 servers MUST support a security mechanism for protection of audio =
media sessions. MRCPv2 clients that originate or consume audio similarly =
MUST support a security mechanism for protection of the =
audio.&nbsp;</span></font></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>------<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Or would you prefer this text that includes the recommendation =
of SRTP?
&nbsp;(Which I noticed you did in the RTP payloads spec - and it makes =
sense to
me to provide some basic guidance.):<o:p></o:p></span></font></p>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>------<o:p></o:p></span></font></p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><font size=3D1 =
face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica'>12.3. Media session =
protection&nbsp;</span></font></span><o:p></o:p></pre><pre><span
class=3Dapple-style-span><font size=3D1 face=3DHelvetica><span =
style=3D'font-size:9.0pt;
font-family:Helvetica'>Sensitive data is also carried on media sessions =
terminating on MRCPv2 servers (the other end of a media channel may or =
may not be on the MRCPv2 client). This data includes the user's spoken =
utterances &nbsp; &nbsp;and the output of text-to-speech operations. =
MRCPv2 servers MUST support a security mechanism for protection of audio =
media sessions. MRCPv2 clients that originate or consume audio similarly =
MUST support a security mechanism for protection of the audio. If =
appropriate,&nbsp;usage of the Secure Real-time Transport Protocol =
(SRTP)&nbsp;[RFC3711] is =
recommended.</span></font></span><o:p></o:p></pre></div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>------<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Regards,<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Dan<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Regards,<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>Dan<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'>On Jul 14, 2009, at 4:55 PM, Roni Even =
wrote:<o:p></o:p></span></font></p>

</div>

<p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><font size=3D3
face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>Dan,</span><=
/font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>This is the =
general
idea. The major reason is that there are various ways to protect the =
data and
if you are not mandating one for interoperability then it can be more =
general</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;</span=
></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>For example =
we have
the following text when discussing security in the RTP payloads =
specifications.</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;</span=
></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>RTP packets =
using
the payload format defined in this specification</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 are
subject to the security considerations discussed in the =
RTP</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

specification [RFC3550] and any appropriate RTP profile.&nbsp; The =
main</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

security considerations for the RTP packet carrying the RTP =
payload</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 format
defined within this memo are confidentiality, integrity, =
and</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 source
authenticity.&nbsp; Confidentiality is achieved by encryption =
of</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 the RTP
payload.&nbsp; Integrity of the RTP packets is achieved through =
a</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

suitable cryptographic integrity protection mechanism.&nbsp; Such =
a</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

cryptographic system may also allow the authentication of the =
source</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 of the
payload.&nbsp; A suitable security mechanism for this RTP =
payload</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 format
should provide confidentiality, integrity protection, and =
at</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 least
source authentication capable of determining if an RTP =
packet</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 is from
a member of the RTP session.</span></font><font color=3Dblack><span
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;</span=
></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 Note
that the appropriate mechanism to provide security to RTP =
and</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

payloads following this memo may vary.&nbsp; It is dependent on =
the</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

application, the transport, and the signaling protocol =
employed.</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

Therefore, a single mechanism is not sufficient, although =
if</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

suitable, usage of the Secure Real-time Transport Protocol =
(SRTP)</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

[RFC3711] recommended.&nbsp; Other mechanisms that may be used are =
IPsec</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=

[RFC4301] Transport Layer Security (TLS) [RFC5246] (RTP over =
TCP);</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;&nbsp;=
 other
alternatives may exist.</span></font><font color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;</span=
></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>Roni =
Even</span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D2 color=3D"#1f497d" =
face=3DCalibri><span
style=3D'font-size:11.0pt;font-family:Calibri;color:#1F497D'>&nbsp;</span=
></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

<div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt;
border-width:initial;border-color:initial'>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in;
border-width:initial;border-color:initial'>

<div>

<p class=3DMsoNormal><b><font size=3D2 color=3Dblack face=3DTahoma><span
style=3D'font-size:10.0pt;font-family:Tahoma;color:black;font-weight:bold=
'>From:</span></font></b><span
class=3Dapple-converted-space><font size=3D2 color=3Dblack =
face=3DTahoma><span
style=3D'font-size:10.0pt;font-family:Tahoma;color:black'>&nbsp;</span></=
font></span><font
size=3D2 color=3Dblack face=3DTahoma><span =
style=3D'font-size:10.0pt;font-family:Tahoma;
color:black'><a =
href=3D"mailto:rai-bounces@ietf.org">rai-bounces@ietf.org</a> [<a
href=3D"mailto:rai-bounces@ietf.org">mailto:rai-bounces@ietf.org</a>]<spa=
n
class=3Dapple-converted-space>&nbsp;</span><b><span =
style=3D'font-weight:bold'>On
Behalf Of<span class=3Dapple-converted-space>&nbsp;</span></span></b>Dan =
York<br>
<b><span style=3D'font-weight:bold'>Sent:</span></b><span
class=3Dapple-converted-space>&nbsp;</span>Tuesday, July 14, 2009 11:16 =
PM<br>
<b><span style=3D'font-weight:bold'>To:</span></b><span
class=3Dapple-converted-space>&nbsp;</span>Roni Even<br>
<b><span style=3D'font-weight:bold'>Cc:</span></b><span
class=3Dapple-converted-space>&nbsp;</span>'Daniel Burnett';<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;
'Saravanan Shanmugham';<span =
class=3Dapple-converted-space>&nbsp;</span><a
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><br>
<b><span style=3D'font-weight:bold'>Subject:</span></b><span
class=3Dapple-converted-space>&nbsp;</span>Re: [RAI] RAI review of
draft-ietf-speechsc-mrcpv2-19</span></font><font color=3Dblack><span
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Roni,<o:p></o:p></span></font></p>=


</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>The current text at&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-=
12.3">http://tools.ietf.org/html/draft-ietf-speechsc-mrcpv2-19#section-12=
.3</a><span
class=3Dapple-converted-space>&nbsp;</span>is:<o:p></o:p></span></font></=
p>

</div>

</div>

<div><pre><span class=3Dapple-style-span><font size=3D1 color=3Dblack =
face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>------</span>=
</font></span><font
color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></pre><pre><span
class=3Dapple-style-span><font size=3D1 color=3Dblack =
face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>12.3. Media =
session protection&nbsp; </span></font></span><font
color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></pre><pre><span
class=3Dapple-style-span><font size=3D1 color=3Dblack =
face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances and the output =
of text-to-speech operations. MRCPv2 servers MUST support SRTP for =
protection of audio media sessions. MRCPv2 clients that originate or =
consume audio similarly MUST support SRTP. Alternative media channel =
protection MAY be used if desired (e.g. =
IPSEC).</span></font></span><font
color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></pre></div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>------<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Based on your comments and the =
srtp-not-mandatory
draft (which was just revised to&nbsp;<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03">=
http://tools.ietf.org/html/draft-ietf-avt-srtp-not-mandatory-03</a><span
class=3Dapple-converted-space>&nbsp;</span>), my understanding would be =
that you
are advocating something more like this:<o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>------<o:p></o:p></span></font></p=
>

</div>

</div>

<div><pre><span class=3Dapple-style-span><font size=3D3 color=3Dblack =
face=3DHelvetica><span
style=3D'font-size:12.0pt;font-family:Helvetica;color:black'>12.3. Media =
session protection&nbsp;</span></font></span><font
color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></pre><pre><span
class=3Dapple-style-span><font size=3D3 color=3Dblack =
face=3DHelvetica><span
style=3D'font-size:12.0pt;font-family:Helvetica;color:black'>Sensitive =
data is also carried on media sessions terminating on MRCPv2 servers =
(the other end of a media channel may or may not be on the MRCPv2 =
client). This data includes the user's spoken utterances &nbsp; =
&nbsp;and the output of text-to-speech operations. MRCPv2 servers MUST =
support a security mechanism for protection of audio media sessions. =
MRCPv2 clients that originate or consume audio similarly MUST support a =
security mechanism for protection of the =
audio.&nbsp;</span></font></span><font
color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></pre></div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>------<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Is that an accurate summary of =
your
feedback? &nbsp;Would that text be =
acceptable?<o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Regards,<o:p></o:p></span></font><=
/p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Dan<o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>On Jul 9, 2009, at 4:56 PM, Roni =
Even
wrote:<o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><font size=3D3 =
color=3Dblack
face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt;color:black'><br>
<br>
<o:p></o:p></span></font></p>

</div>

<div>

<div>

<p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><font size=3D3 =
color=3Dblack
face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt;color:black'>Eric,<br>
My comment is that in this case in AVT we say that you do not need =
to<br>
mandate SRTP but mandate a security mechanism that can be &nbsp;not only =
SRTP
but<br>
in a different layer like ipsec. This is why I gave a reference to =
the<br>
srtp-not-mandatory draft<br>
<br>
Roni<br>
<br>
<br>
<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>-----Original =
Message-----<o:p></o:p></span></font></p>

</div>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>From: Eric Burger [<a
href=3D"mailto:eburger@standardstrack.com">mailto:eburger@standardstrack.=
com</a>]<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Sent: Thursday, July 09, 2009 =
11:28 PM<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>To: Roni =
Even<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Cc: Saravanan Shanmugham; Daniel =
Burnett;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:speechsc@ietf.org">speechsc@ietf.org</a>;<o:p></o:p></span=
></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'><a =
href=3D"mailto:rai@ietf.org">rai@ietf.org</a><o:p></o:p></span></font></p=
>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Subject: Re: RAI review of
draft-ietf-speechsc-mrcpv2-19<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>The reality is that NO ONE has =
implemented
any security to date. The<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>GENART reviewer raised the same =
issue, and
so far the work group has<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>the same response: MRCPv2 (the =
speechsc
work group) is not planning on<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>figuring out which of the seven =
key
exchange mechanisms to use in<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>SIP. &nbsp;We are counting on the
community publishing something, and<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>people using it. &nbsp;After all, =
we are
the &quot;using SIP for media resource<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>control&quot; work group, not the
&quot;media resource control work group =
using<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>something like SIP for =
control.&quot;<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>Does this work for =
you?<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>On Jul 7, 2009, at 3:40 PM, Roni =
Even
wrote:<o:p></o:p></span></font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>[snip]<o:p></o:p></span></font></p=
>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>18. &nbsp;&nbsp;In section 12.3 =
the
suggestion is to use SRTP as the mandatory<o:p></o:p></span></font></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>interoperability mode. If the =
reason for mandating
SRTP is for a<o:p></o:p></span></font></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>common mode you should also =
decide on a
key exchange mechanism. I<o:p></o:p></span></font></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>suggest you look at<a
href=3D"http://tools.ietf.org/html/draft-ietf-avt-srtp-">http://tools.iet=
f.org/html/draft-ietf-avt-srtp-</a><o:p></o:p></span></font></p>

</div>

</blockquote>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>not-mandatory-02<o:p></o:p></span>=
</font></p>

</div>

</blockquote>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<blockquote style=3D'margin-top:5.0pt;margin-bottom:5.0pt'>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>for discussion on media =
security.<o:p></o:p></span></font></p>

</div>

</blockquote>

</blockquote>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'><br>
<br>
_______________________________________________<br>
RAI mailing list<br>
<a href=3D"mailto:RAI@ietf.org">RAI@ietf.org</a><br>
<a =
href=3D"https://www.ietf.org/mailman/listinfo/rai">https://www.ietf.org/m=
ailman/listinfo/rai</a><o:p></o:p></span></font></p>

</div>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>--&nbsp;</spa=
n></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Dan York, =
Director of
Conversations</span></font><font color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Voxeo =
Corporation<span
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a></span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Phone:
+1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span></span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Join the =
Voxeo
conversation:</span></font><font color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Blogs:<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a></span></font><=
font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Twitter:<span=

class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a><span
class=3Dapple-converted-space>&nbsp;</span>&nbsp;<a
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a></span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Facebook:<spa=
n
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
/span></font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><font size=3D1 =
color=3Dblack
face=3DHelvetica><span =
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><br>
<br>
</span></font><font color=3Dblack><span =
style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>&nbsp;</span>=
</font><font
color=3Dblack><span style=3D'color:black'><o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dblack face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:black'>&nbsp;<o:p></o:p></span></font></p=
>

</div>

</div>

</div>

</div>

</div>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

<div>

<div>

<div>

<div>

<div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>--&nbsp;<o:p>=
</o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Dan York, =
Director of
Conversations<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Voxeo =
Corporation<span
class=3Dapple-converted-space>&nbsp;</span>&nbsp;&nbsp;<a
href=3D"http://www.voxeo.com">http://www.voxeo.com</a>&nbsp;<span
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:dyork@voxeo.com">dyork@voxeo.com</a><o:p></o:p></span></fo=
nt></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Phone:
+1-407-455-5859&nbsp;<span =
class=3Dapple-converted-space>&nbsp;&nbsp;&nbsp;</span>Skype:
danyork&nbsp;<span =
class=3Dapple-converted-space>&nbsp;</span><o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Join the =
Voxeo
conversation:<o:p></o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Blogs: <a
href=3D"http://blogs.voxeo.com">http://blogs.voxeo.com</a><o:p></o:p></sp=
an></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Twitter: <a
href=3D"http://twitter.com/voxeo">http://twitter.com/voxeo</a> &nbsp;<a
href=3D"http://twitter.com/danyork">http://twitter.com/danyork</a><o:p></=
o:p></span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'>Facebook: <a
href=3D"http://www.facebook.com/voxeo">http://www.facebook.com/voxeo</a><=
o:p></o:p></span></font></p>

</div>

</div>

<div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><font size=3D1 =
color=3Dblack
face=3DHelvetica><span =
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D1 color=3Dblack face=3DHelvetica><span
style=3D'font-size:9.0pt;font-family:Helvetica;color:black'><o:p>&nbsp;</=
o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><o:p>&nbsp;</o:p></span></font></p>

</div>

</div>

</div>

</body>

</html>

------=_NextPart_000_002C_01CA0547.C0955730--

