: [Fwd: Comments on draft-ietf-aaa-diameter-sip-app-05.txt]

Miguel Garcia <[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Howdy!

I got an e-mail with some comments to the Diameter SIP application 
version -05 (the latest version is -06), but I think there are no 
conflicts with the section numbers, so you can take a look at either 
version -05 or -06.

I am posting this so that people can take a look at these comments. I 
will send my answers later today, but I certainly welcome answers from 
anyone or further comments.

BR,

       Miguel

----------


1) In chapter 5.4 SIP Server is not Authenticating the Request. The 
Diameter Server is authenticating the request.

2) In chapter 7.7 it is written: 'Unlike the Diameter UAR command, MAR 
does not store any state in the Diameter server'. What does this mean? 
What state? Authentication pending flag is set in MAR...

3) In chapter 8.5 it is written: ' If the SIP-Auth-Data-Item is used to 
convey a SIP-Authenticate grouped AVP, then the Diameter client MUST 
send a maximum of one authentication data item'. Isn't the 
SIP-Authenticate used by Diameter server?

4) In chapter 8.6 and 10  it is talked about authentication vectors. In 
HTTP Digest authentication there are no really any authentication 
vectors in my opinion and the draft is not only about AKA authentication 
in IMS.

5) Chapter 10, 3rd paragraph: The calculation of H(A1) doesn't depend on 
qop, but on the algorithm. See chapter 3.2.2.2 of RFC 2617.

6) In chapter 10 from fourth paragraph the reader gets the impression 
SIP-Authentication-Scheme AVP will contain data (typically a challenge 
of some kind), which is not true.

7) Chapter 10. It is not clearly told, how many credentials the Diameter 
client must send to the Diameter server. First there can be more than 
one credentail and later on the Diameter client must send zero or 
exactly one credentail to the Diameter server. It is told also that the 
Diameter server may include one or more SIP-Auth-Data-Item AVPs to 
provide further authentication vectors to the SIP server. This is 
possible only if it is known that the realm and method of the next 
request will be the same and qop is not 'auth-int'. This is possible of 
course also if the Diameter client sent several credentials, but does 
the text refer to this case?


-- 
Miguel A. Garcia           tel:+358-50-4804586
Nokia Research Center      Helsinki, Finland
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.