Re: : issue with expected response calculation
Miguel Garcia <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Hi Jo:
Thanks for your comment. I agree with you that the paragraph in Section
8.5.6.1 (Note that...) does not make sense again, and it is related to
issue 40. It should have been fixed together.
Since it seems that we will add support for client generated nonces,
there will be new versions of the Diameter SIP app, and at that time we
will fix this paragraph, and add the considerations about the MD5-sess
you mentioned.
Thanks a lot,
Miguel
Jo Hermans wrote:
> Replying on my own question ...
>
> On 4/12/05, Jo Hermans <[email protected]
> <mailto:[email protected]>> wrote:
>
> I have a problem with paragraph 8.5.6.1 <http://8.5.6.1> in
> draft-ietf-aaa-diameter-sip-app-07 , 3th paragraph ("Please note
> that the expected response ...")
>
> The draft mentions that the expected response calculation can't be
> done when the SIP UA has sent a expected response based on client
> nonces. It then mentions that this is the case when the
> qop-parameter is present in the client request.
>
> That last part I don't understand. I though that H(A1) is dependent
> on the algorithm, not qop. Qop has only influence on the A2 and
> digest, which are both calculated in the Diameter Client (SIP
> Server). See also
> <http://danforsberg.info:8080/draft-ietf-aaa-diameter-sip/issue40>
>
> But even then I don't understand. I think that the Diameter Server
> does has the client-nonces available (they're in the
> SIP-Authorization AVP, and were used to calculate the request digest
> !)), and is able to calculate a H(A1). Even if MD5-sess was used, it
> could still calculate H(A1). MD5-sess also has the added advantage
> that H(A1) could only be used once, which is also the reason why
> draft-sterman-aaa-sip-04.txt doesn't want to use MD5 unless the
> message is protected against eavesdropping.
>
>
> Now I see that the Digest-HA1 attribute is present in the
> SIp-Authenticate AVP, which probably never saw a cnonce at all, because
> it's part of the challenge. My mistake was that I thought that it was in
> SIP-Authorisation too.
>
> This also means that if a server decides to include Digest-Ha1 to assist
> the SIP-server (to avoid that the next packet with the Sip-Authorisation
> should be forwarded to the server too), then it should not offer the SIP
> UA to use MD5-sess, because that includes client-nonces in A1. Qop is
> not a problem, despite paragraph 3 in section 8.5.6.1 <http://8.5.6.1>
> of sip-app-07.
>
> I agree that if qop is missing and algorithm is MD5, client-nonces
> aren't used at all (backwards compatibility with RFC2069). H(A1)
> might be stored inside the Diameter Client (SIP server) when it's
> first received, and reused later on. Is it this that the draft is
> alluding to ?
>
> --
> Jo Hermans
>
> "Eagles may soar, but weasels aren't sucked into jet engines"
>
>
>
>
> --
> Jo Hermans
> www.bluesweb.org <http://www.bluesweb.org>
>
> "Eagles may soar, but weasels aren't sucked into jet engines"
--
Miguel A. Garcia tel:+358-50-4804586
sip:[email protected]
Nokia Research Center Helsinki, Finland