Re: : ISSUE: SIP application policy considered unmanageable

Miguel Garcia <[email protected]> Tue, 18 Oct 2005 22:39:16 +0300
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hi David:

My criticism was towards adding this mode of operation to the Diameter 
draft (not to the RADIUS), imported from the RADIUS draft, where it is 
hard to manage (and as I indicated, I don't have a good solution to make 
it better for the time being).

/Miguel

Nelson, David wrote:

> Miguel Garcia writes...
> 
> 
>>Is it crap? Probably, time will say. Will it be used? Probably not,
> 
> time
> 
>>will say. Does it bring a configuration nightmare, due to the required
>>synchronization between the server and the client? Yes. Can we improve
>>this nightmare? I don't know how, perhaps removing the generation of
>>nonces in the client... But if someone has a better proposal, I am
> 
> able
> 
>>to listen to. I think "compatilibity with RADIUS" is the driver here.
> 
> 
> The RADEXT WG was advised that 3PPG2 has already deployed the mode of
> nonce generation in the client, and requested that feature remain in the
> RADIUS Digest Authentication specification.  This statement was made at
> the RADEXT WG session at IETF-63.  Therefore, I would presume that the
> feature is in current use.  Whether it will be deprecated in future
> releases or deployments is an open question, of course.
> 
> 

-- 
Miguel A. Garcia           tel:+358-50-4804586
sip:[email protected]
Nokia Research Center      Helsinki, Finland