RE: : ISSUE, SIP, authentication parameters

<[email protected]> Tue, 25 Oct 2005 16:52:34 +0300
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hi!

> First I am sorry to say that the time for the 3rd WGLC is over, so we 
> are not ready to make changes during this process. We can do changes 
> during the IETF Last call, if those changes are justified.

I propose new last call is needed or the changes should be done
during author's 48 hours.


> We discussed this issue about 2 years ago,

I doubt we have discussed all the issues in my issue :)


> and we wanted to add a possibility to enable the scenario 
> described in Sections 5.5 and 5.6, where an outbound proxy is
> authorizing request. Some users might be authorized to use any
> SIP method, others only a few of them. In order to do this,
> the SIP-Method must be present.

I think in order to do that it's enough to define that the default-behavior
of Diameter server is that all SIP-methods are authorized. This is applied
in the case where no Digest-Method is received. If the Diameter server receives
Digest-Method then it can apply some other policy. This is what the text
I proposed does. So there is no need to have SIP-Method as required
AVP.


> And at that point in time, the user might not have sent any
> Authorization header, so the Digest-Method might not be present.

The Diameter client can fill the Digest-Method to the SIP-Authorization
AVP even if there is no Authorization header in the SIP-request.

What about the other problems I indicated in the issue?


BR,
Mikko


> -----Original Message-----
> From: Miguel Garcia [mailto:[email protected]]
> Sent: 25 October, 2005 15:55
> To: Aittola Mikko (Nokia-NET/Tampere)
> Cc: [email protected]
> Subject: Re: [AAA-WG]: ISSUE, SIP, authentication parameters
> 
> 
> Hi:
> 
> First I am sorry to say that the time for the 3rd WGLC is over, so we 
> are not ready to make changes during this process. We can do changes 
> during the IETF Last call, if those changes are justified.
> 
> With respect your comment. We discussed this issue about 2 years ago, 
> and we wanted to add a possibility to enable the scenario 
> described in 
> Sections 5.5 and 5.6, where an outbound proxy is authorizing request. 
> Some users might be authorized to use any SIP method, others 
> only a few 
> of them. In order to do this, the SIP-Method must be present. And at 
> that point in time, the user might not have sent any Authorization 
> header, so the Digest-Method might not be present.
> 
> Sorry, but NO.
> 
> /Miguel
> 
> [email protected] wrote:
> 
> > Description of issue: Authentication parameters
> > Submitter name: Mikko Aittola
> > Submitter email address: [email protected]
> > Date first submitted: 25 Oct 05
> > Document: sip (v. 10)
> > Comment type: T
> > Priority: S
> > Sections: 7.7, 7.8, 8.5.3, 8.5.4, 8.5.5
> > Rationale/Explanation of issue:
> > 
> > SIP-Method is defined to be required AVP in MAR-command.
> > Is there really need for this to be required AVP?
> > I think Diameter server doesn't necessarily need to consider
> > what is the SIP-method the SIP-server is asking to authenticate.
> > 
> > Furthermore, there is already optional Digest-Method AVP
> > in SIP-Authorization grouped AVP. This can be used for
> > the same purpose as SIP-Method AVP.
> > 
> > SIP-Authorization grouped AVP contains required AVP
> > Digest-Username. This is duplicate information with
> > the User-Name AVP sent in the MAR-command.
> > 
> > It seems the case where Diameter server sends HA1 in MAA
> > and client calculates and checks the response has not been
> > taken into account when the required contents of SIP-Authorization,
> > SIP-Authenticate, and SIP-Authentication-Info AVP have been defined.
> > 
> > It is not clear what is included to MAA message in case
> > Diameter server has checked the response successfully.
> > It might be useful if the Diameter client receives a confirmation
> > of the auth-scheme applied by the Diameter-server.
> > 
> > 
> > Requested changes:
> > 
> > 1. Remove SIP-Method AVP from the spec
> > 2. Remove Digest-Username from the spec. (If needed add text where
> >    it is explained that Digest-Username is translated to
> >    User-Name in the case of Radius-Diameter translation.)
> > 3. Change Digest-Nonce to optional in SIP-Authenticate
> > 4. Change the following AVPs to optional in SIP-Authorization AVP:
> >    Digest-Nonce, Digest-URI, Digest-Response
> > 5. Change Digest-Nextnonce to optional in 
> SIP-Authentication-Info AVP
> > 6. After Diameter server has checked that the response is ok
> >    it returns MAA where result-code is SUCCESS, and 
> SIP-Auth-Data-Item
> >    with the SIP-Authentication-Scheme AVP.
> > 
> > 7. Change the following text in Section 7.8:
> >    If the SIP-Methods AVP value of the Diameter MAR message 
> is set to
> >    REGISTER and a User-Name AVP is present, then the Diameter server
> >    MUST authorize that User-Name AVP value is able to use the URI
> >    included in the SIP-AOR AVP.  If this authorization fails, the
> >    Diameter server must set the Result-Code AVP to
> >    DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter
> >    Multimedia-Auth-Answer (MAA) message.
> >  To:
> >    If the Digest-Method AVP value is either absent or 
> received with a
> >    value REGISTER in the Diameter MAR message and a User-Name AVP is
> >    present, then the Diameter server MUST authorize that 
> User-Name AVP
> >    value is able to use the URI included in the SIP-AOR 
> AVP.  If this
> >    authorization fails, the Diameter server must set the 
> Result-Code AVP to
> >    DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter
> >    Multimedia-Auth-Answer (MAA) message.
> > 
> > 
> > BR,
> > Mikko
> > 
> > 
> > PS. Sorry for the late submission..
> > 
> 
> -- 
> Miguel A. Garcia           tel:+358-50-4804586
> sip:[email protected]
> Nokia Research Center      Helsinki, Finland
> 
>