Re: : Re: Comments on draft-ietf-aaa-diameter-sip-app-05.txt

Miguel Garcia <[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Cullen:

The Diameter server never reveals the users' password to the SIP server. 
It reveals H(A1) (Digest), which is used to calculate the expected 
response, but not the password.

In any case, I will try to add more clarifications to this part of the 
draft.

- Miguel

Cullen Jennings wrote:

> 
> Sure that wording sounds better. Not a big deal to me one way or another 
> but it was a part that I thought would leave people somewhat confused. 
> Might want to consider phrasing it more as if the Diameter server does 
> not want to reveal the users password to the SIP server then blah blah 
> blah. Really this is a polishing detail, I think that everyone who needs 
> to really implement and understand this stuff will get what this is all 
> about no matter what we put here. I don't think the words here are 
> critical to people making products that successfully interoperate so I 
> really don't want to hold things up with too much wordsmiting on this.
> 
> Cullen
> 
> 
> On 1/17/05 3:47 AM, "[email protected]" <[email protected]> 
> wrote:
> 
>     Hi Miguel & Cullen,
> 
>>  I am not sure if this message has been distributed by the AAA mailing
>>  list.
> 
>     I don't think it was.
> 
>>  In any case, read below Cullen's concerns and my answers inline.
>>
>>  Cullen Jennings wrote:
>>  > I just reviewed the stuff on how MAR/MAA fit in with SIP digest
>     auth - the
>>  > draft is very nice and complete, and about as exciting as
>     reading MIBs :-)
>>  >
>>  > One trivial comment section 10 second para - the expression "retain
>>  > authentication of the user" left me puzzled for a bit by what it
>     meant.
>>
>>  Ok, I see it may be missleading. The idea to express is "if the
>     Diameter
>>  server wants to assue that authentication will take place in the own
>>  Diameter server (as opposed to a delegated authentication taking
>     place
>>  in the SIP server) ...."
> 
>     I think you mean assume in the second sentence; Cullen, is this text
>     better?
> 
>>  > It might be worth a comment that on system where the SIP that
>     are using
>>  > Digest inside of TLS where only the proxy has a certificate,
>     that using the
>>  > HA1 mode greatly reduces the load on diameter servers. On the
>     other hand
>>  > this might be obvious to anyone who cares so perhaps it is not
>     worth
>>  > mentioning. I don't really care much but that's my 0.5 cents.
>>
>>  It is fine, we can add some motivation text indicating so.
> 
>     Great; after that, I think we might be done.
> 
>     John
> 
> 

-- 
Miguel A. Garcia           tel:+358-50-4804586
Nokia Research Center      Helsinki, Finland
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.