Application-Layer Protocol Negotiation (ALPN) for WebRTC
RFC 8833
Note: This ballot was opened for revision 03 and is now closed.
(Ben Campbell) Yes
Comment (2016-05-03 for -03)
No email
send info
send info
Should I-D.ietf-rtcweb-security-arch be a normative reference, due to the citation in section 4?
Alissa Cooper Yes
(Jari Arkko) No Objection
Comment (2016-05-04 for -03)
No email
send info
send info
Note: There has been no answer to Russ Housley's Gen-ART review comments yet.
(Alia Atlas) No Objection
Deborah Brungard No Objection
(Stephen Farrell) No Objection
Comment (2016-05-04 for -03)
No email
send info
send info
- I suspect the term "confidential" as used here will turn out to mislead or confuse some folks. The meaning is clear if one reads the draft, but of course many people will just read some stackexchange answer. It's probably too late to try change that unless someone has a good term beginning with "c" to use for c-werbrtc. The potential for confusion I think will be that the other label might be assumed to not use a good confidentiality mechanism on the wire, so folks might get concerned that e.g. their DataChannel stuff can be read by a middlebox. (I just mention this in case the concern is either new or has been bubbling up in the WG, feel entirely free to ignore me if you want.) - I forget how the screen sharing issue for WebRTC was resolved. In any case, do the handling of screen sharing and c-webrtc interact? Do you need to explain that there's some non-browser "access" (origination really) of media on the screen-sharer's machine? - "clever arrangement of mirrors" - that is a nice way to explain the futility of DRM :-)
(Joel Jaeggli) No Objection
(Suresh Krishnan) No Objection
(Mirja Kühlewind) No Objection
(Terry Manderson) No Objection
(Alexey Melnikov) No Objection
Comment (2016-04-28 for -03)
No email
send info
send info
Please excuse my ignorance (pointers would be appreciated, if this is explained elsewhere): do RTP intermediary need to be updated to understand this spec? If yes, how can you enforce requirements on "c-webrtc"?
(Kathleen Moriarty) No Objection
Comment (2016-05-04 for -03)
No email
send info
send info
I agree with Stephen's comments on the word confidentiality, but can't think of an alternate word. I think text describing how this is limited would be helpful in the introduction. The clearest (at least to me) description of what is meant by confidentiality doesn't appear until the security considerations section.