Re: : ISSUE: SIP application policy considered unmanageable
Miguel Garcia <[email protected]> Tue, 18 Oct 2005 22:39:16 +0300
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Hi David: My criticism was towards adding this mode of operation to the Diameter draft (not to the RADIUS), imported from the RADIUS draft, where it is hard to manage (and as I indicated, I don't have a good solution to make it better for the time being). /Miguel Nelson, David wrote: > Miguel Garcia writes... > > >>Is it crap? Probably, time will say. Will it be used? Probably not, > > time > >>will say. Does it bring a configuration nightmare, due to the required >>synchronization between the server and the client? Yes. Can we improve >>this nightmare? I don't know how, perhaps removing the generation of >>nonces in the client... But if someone has a better proposal, I am > > able > >>to listen to. I think "compatilibity with RADIUS" is the driver here. > > > The RADEXT WG was advised that 3PPG2 has already deployed the mode of > nonce generation in the client, and requested that feature remain in the > RADIUS Digest Authentication specification. This statement was made at > the RADEXT WG session at IETF-63. Therefore, I would presume that the > feature is in current use. Whether it will be deprecated in future > releases or deployments is an open question, of course. > > -- Miguel A. Garcia tel:+358-50-4804586 sip:[email protected] Nokia Research Center Helsinki, Finland