Re: I-D Action:draft-kaplan-sipping-pai-responses-00.txt
2008-12-01 08:59:27 GMT
Hadriel, Thanks for writing this. However, in my opinion it still suffers from the same problem that we had with update-pai-06 (where we just said that the proxy must have authenticated the source of the response by some means) and update-pai-05 (where we cited one possible circumstance where authentication could be assumed, i.e., when an earlier request over the same TLS connection had been digest-authenticated). We received objections to 06 because it did not cite at least one example of how to achieve authentication and we received objections to 05 because the mechanism is broken (there could be an intermediary that terminates the TLS connection, so there is no guarantee that the UA that was previously authenticated is the same as the UA that sends the response). I think there are only two ways forward on this: 1. Somebody comes up with some text that describes a plausible way of achieving authentication using present mechanisms. For example, if my understanding is correct, I think the 3GPP mechanism relies on using the same credentials for authenticating the UA and the underlying transport, and hence the broken behaviour I described above does not apply. I really wanted somebody else to provide some text, and I had hoped Keith would do this. 2. We define a new mechanism. It has been stated that something based on sip-outbound might be possible, but I don't really know what people have in mind. As Cullen observes, this approach would most likely need to be pursued in SIP rather than SIPPING. John > -----Original Message-----(Continue reading)
RSS Feed