: ISSUE: SIP application policy considered unmanageable

"Glen Zorn (gwz)" <[email protected]> Mon, 17 Oct 2005 23:25:57 -0700
Newsgroups gmane.ietf.aaa
Message-ID <4C0FAAC489C8B74F96BEAD85EAEB2625E2427F@xmb-sjc-215.amer.cisco.com>
Description of issue: SIP application policy considered unmanageable
Submitter name: Glen Zorn
Submitter email address: [email protected]
Date first submitted: 17 Oct 05
Document: sip
Comment type: T
Priority: 1
Section: All
Rationale/Explanation of issue: Section 5.2 says "Whenever a SIP server
receives a SIP request, it has to decide whether nonces for HTTP Digest
authentication will be locally generated in the Diameter client or
remotely in the Diameter server.  This is a decision derived from a
policy that is configured in the SIP server/Diameter server."  It
appears that this policy may vary from client to client and that all of
these varied policies must be synchronized with the Diameter servers.  I
see a couple of problems in this scheme: first, it flies in the face of
the general rule that AAA servers dictate policy & clients follow it;
secondly, in any but a tiny network these various policies will present
a major management burden. 

Requested change: Make general recommendations as to the generation of
nonces for the various flavors of authentication but remove the
requirement of individual configuration of every client.