: [Fwd: Comments on draft-ietf-aaa-diameter-sip-app-05.txt]
Miguel Garcia <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Howdy!
I got an e-mail with some comments to the Diameter SIP application
version -05 (the latest version is -06), but I think there are no
conflicts with the section numbers, so you can take a look at either
version -05 or -06.
I am posting this so that people can take a look at these comments. I
will send my answers later today, but I certainly welcome answers from
anyone or further comments.
BR,
Miguel
----------
1) In chapter 5.4 SIP Server is not Authenticating the Request. The
Diameter Server is authenticating the request.
2) In chapter 7.7 it is written: 'Unlike the Diameter UAR command, MAR
does not store any state in the Diameter server'. What does this mean?
What state? Authentication pending flag is set in MAR...
3) In chapter 8.5 it is written: ' If the SIP-Auth-Data-Item is used to
convey a SIP-Authenticate grouped AVP, then the Diameter client MUST
send a maximum of one authentication data item'. Isn't the
SIP-Authenticate used by Diameter server?
4) In chapter 8.6 and 10 it is talked about authentication vectors. In
HTTP Digest authentication there are no really any authentication
vectors in my opinion and the draft is not only about AKA authentication
in IMS.
5) Chapter 10, 3rd paragraph: The calculation of H(A1) doesn't depend on
qop, but on the algorithm. See chapter 3.2.2.2 of RFC 2617.
6) In chapter 10 from fourth paragraph the reader gets the impression
SIP-Authentication-Scheme AVP will contain data (typically a challenge
of some kind), which is not true.
7) Chapter 10. It is not clearly told, how many credentials the Diameter
client must send to the Diameter server. First there can be more than
one credentail and later on the Diameter client must send zero or
exactly one credentail to the Diameter server. It is told also that the
Diameter server may include one or more SIP-Auth-Data-Item AVPs to
provide further authentication vectors to the SIP server. This is
possible only if it is known that the realm and method of the next
request will be the same and qop is not 'auth-int'. This is possible of
course also if the Diameter client sent several credentials, but does
the text refer to this case?
--
Miguel A. Garcia tel:+358-50-4804586
Nokia Research Center Helsinki, Finland