Session Traversal Utilities for NAT Usage for Consent Freshness
RFC 7675, “Session Traversal Utilities for NAT Usage for Consent Freshness”, is a Proposed Standard document published in October 2015 by M. Perumal, D. Wing, R. Ravindranath, T. Reddy, M. Thomson. The canonical text is published by the RFC Editor.
Abstract
To prevent WebRTC applications, such as browsers, from launching attacks by sending traffic to unwilling victims, periodic consent to send needs to be obtained from remote endpoints.
This document describes a consent mechanism using a new Session Traversal Utilities for NAT (STUN) usage.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7675 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7674 Clarification of the Flowspec Redirect Extended Community
- RFC 7676 IPv6 Support for Generic Routing Encapsulation
- RFC 7673 Using DNS-Based Authentication of Named Entities TLSA Records with SRV Records
- RFC 7677 SCRAM-SHA-256 and SCRAM-SHA-256-PLUS Simple Authentication and Security Layer Mechanisms
- RFC 7672 SMTP Security via Opportunistic DNS-Based Authentication of Named Entities Transport Layer Security
- RFC 7678 Attribute-Value Pairs for Provisioning Customer Equipment Supporting IPv4-Over-IPv6 Transitional Solutions
- RFC 7671 The DNS-Based Authentication of Named Entities Protocol: Updates and Operational Guidance
- RFC 7681 Email Exchange of Secondary School Transcripts