Re: : Re: Comments on draft-ietf-aaa-diameter-sip-app-05.txt
Miguel Garcia <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Loughney John (Nokia-NRC/Helsinki) wrote: > Hi Miguel & Cullen, > > >>I am not sure if this message has been distributed by the AAA mailing >>list. > > > I don't think it was. > > >>In any case, read below Cullen's concerns and my answers inline. >> >>Cullen Jennings wrote: >> >>>I just reviewed the stuff on how MAR/MAA fit in with SIP digest auth - the >>>draft is very nice and complete, and about as exciting as reading MIBs :-) >>> >>>One trivial comment section 10 second para - the expression "retain >>>authentication of the user" left me puzzled for a bit by what it meant. >> >>Ok, I see it may be missleading. The idea to express is "if the Diameter >>server wants to assue that authentication will take place in the own >>Diameter server (as opposed to a delegated authentication taking place >>in the SIP server) ...." > > > I think you mean assume in the second sentence; Cullen, is this text better? Absolutely, missing 'm'. > > >>>It might be worth a comment that on system where the SIP that are using >>>Digest inside of TLS where only the proxy has a certificate, that using the >>>HA1 mode greatly reduces the load on diameter servers. On the other hand >>>this might be obvious to anyone who cares so perhaps it is not worth >>>mentioning. I don't really care much but that's my 0.5 cents. >> >>It is fine, we can add some motivation text indicating so. > > > Great; after that, I think we might be done. Well, almost. We have an open discussion with the RADIUS authentication document. This may end up in RADIUS defining the SIP-AOR atrribute, in which case the Diameter SIP app will need to "include" it rather than defining. Then we are done. > > John /Miguel -- Miguel A. Garcia tel:+358-50-4804586 Nokia Research Center Helsinki, Finland