RE: : digest issue 11 closure (fwd)
Avi Lior <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <F17FB067A86B2D488382C923C532EAA704F7432B@exch01.bridgewatersys.com> |
Hi David, > -----Original Message----- > From: Nelson, David [mailto:[email protected]] > Sent: Thursday, April 07, 2005 11:30 AM > To: [email protected] > Subject: RE: [AAA-WG]: digest issue 11 closure (fwd) > > > John Loughney writes... > > > What you are suggesting is > > that we should dumb-down Diameter SIP so that it can live > with RADIUS. > > However, I don't think we have a requirement for this. > > Well, the RADEXT WG *does* have a requirement that RADIUS > extensions be interoperable with Diameter. I guess what > you're saying is that the AAA WG does *not* have a > requirement that Diameter be interoperable with RADIUS extensions. > > There are two SIP Digest Authentication protocols, one in > Diameter and one in RADIUS. My understanding is that one > originated in 3GPP and the other originated in 3GPP2. Are > you suggesting that these are disjoint solution sets that > need not interoperate? Not exactly accurate. Diameter SIP was originally based on the 3GPP requirements (Cx interface) but my understanding is that they divereged. 3GPP2 currently is using the Digest authentication for HTTP Digest authentication and not for SIP at all. So 3GPP2 is using not concerned about the SIP part and just the HTTP Digest authentication part which is what the sterman document was originally about. Note that Diameter SIP application does a lot more then RADIUS Digest authentication. So they don't interoperate. RADIUS Digest authentication is just that, Digest authentication and not a SIP application. I raised this concern before. If you want compelete SIP interoperability between RADIUS and Diameter then you need to handle those other messages that Diameter SIP has introduced. In essence you need RADIUS SIP application. So the answer to your last question: "...are these disjoint solutions sets that need not interoperate?" They answer is yes. The intent was to just get the auth part to interoperate that would be nice but if its not achievable so be it. I have my doubts about Diameter SIP. Why did 3GPP not adopt it? Is the model that Diameter SIP supports originates from 3GPP, but does it have general applicablity? Can I take the Diameter SIP and use it for other SIP architectures?