Re: : digest issue 11 closure (fwd)

Miguel Garcia <[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hmmmm... I see the point. But I still believe a translation rule is 
needed, but not in the gateway, but in the RADIUS client (so this makes 
also the rule needed in the gateway).

Imagine: how is the SIP-server/RADIUS-client going to determine that it 
has to generate an Authentication-Info header when the RADIUS server 
returns a next nonce? I guess there is a rule that says "if 
Digest-Nextnonce attribute present, then generate Authentication-Info 
header in SIP". So this is the rule between RADIUS and SIP.

In Diameter SIP app, we don't have this problem, because the 
Digest-Nextnonce would be part of the SIP-Authentication-Info AVP.

So the point I want to make is that, due to the lack of grouped 
attributes in RADIUS, you do need translation rules in RADIUS in order 
to generate the appropriate HTTP/SIP digest header. And we don't have 
this problem in Diameter due to the usage of grouped AVPs. So the 
translation rules are in the RADIUS part of the gateway, not in the 
Diameter. You should fix the RADIUS draft if possible, rather than 
extend translation rules to native Diameter applications.

/Miguel

Jari Arkko wrote:

> Miguel Garcia wrote:
> 
>> Minimizing the "coding" or "mapping table construnction" is a valuable 
>> argument when it has an impact on the processing time. But as I said 
>> before, this time is negligible compared to the time the gateway will 
>> use to process a request, so I don't see the point in destroying the 
>> clear structure we have in the Diameter SIP app for no visible gain.
>>
> Perhaps I didn't make my argument clear, because you seem
> to be talking about a different tradeoff than I am. My worry was
> not anything that happens at run-time, I'm sure a translation
> gateway spends less CPU time re-organizing AVPs than something
> else, say TLS.
> 
> My worry was, however, about the need to have a specific
> translation rule, which increases *implementation* time
> and effort.
> 
> --Jari
> 

-- 
Miguel A. Garcia           tel:+358-50-4804586
Nokia Research Center      Helsinki, Finland
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.