RE: : ISSUE, SIP, authentication parameters
<[email protected]> Tue, 25 Oct 2005 16:52:34 +0300
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Hi! > First I am sorry to say that the time for the 3rd WGLC is over, so we > are not ready to make changes during this process. We can do changes > during the IETF Last call, if those changes are justified. I propose new last call is needed or the changes should be done during author's 48 hours. > We discussed this issue about 2 years ago, I doubt we have discussed all the issues in my issue :) > and we wanted to add a possibility to enable the scenario > described in Sections 5.5 and 5.6, where an outbound proxy is > authorizing request. Some users might be authorized to use any > SIP method, others only a few of them. In order to do this, > the SIP-Method must be present. I think in order to do that it's enough to define that the default-behavior of Diameter server is that all SIP-methods are authorized. This is applied in the case where no Digest-Method is received. If the Diameter server receives Digest-Method then it can apply some other policy. This is what the text I proposed does. So there is no need to have SIP-Method as required AVP. > And at that point in time, the user might not have sent any > Authorization header, so the Digest-Method might not be present. The Diameter client can fill the Digest-Method to the SIP-Authorization AVP even if there is no Authorization header in the SIP-request. What about the other problems I indicated in the issue? BR, Mikko > -----Original Message----- > From: Miguel Garcia [mailto:[email protected]] > Sent: 25 October, 2005 15:55 > To: Aittola Mikko (Nokia-NET/Tampere) > Cc: [email protected] > Subject: Re: [AAA-WG]: ISSUE, SIP, authentication parameters > > > Hi: > > First I am sorry to say that the time for the 3rd WGLC is over, so we > are not ready to make changes during this process. We can do changes > during the IETF Last call, if those changes are justified. > > With respect your comment. We discussed this issue about 2 years ago, > and we wanted to add a possibility to enable the scenario > described in > Sections 5.5 and 5.6, where an outbound proxy is authorizing request. > Some users might be authorized to use any SIP method, others > only a few > of them. In order to do this, the SIP-Method must be present. And at > that point in time, the user might not have sent any Authorization > header, so the Digest-Method might not be present. > > Sorry, but NO. > > /Miguel > > [email protected] wrote: > > > Description of issue: Authentication parameters > > Submitter name: Mikko Aittola > > Submitter email address: [email protected] > > Date first submitted: 25 Oct 05 > > Document: sip (v. 10) > > Comment type: T > > Priority: S > > Sections: 7.7, 7.8, 8.5.3, 8.5.4, 8.5.5 > > Rationale/Explanation of issue: > > > > SIP-Method is defined to be required AVP in MAR-command. > > Is there really need for this to be required AVP? > > I think Diameter server doesn't necessarily need to consider > > what is the SIP-method the SIP-server is asking to authenticate. > > > > Furthermore, there is already optional Digest-Method AVP > > in SIP-Authorization grouped AVP. This can be used for > > the same purpose as SIP-Method AVP. > > > > SIP-Authorization grouped AVP contains required AVP > > Digest-Username. This is duplicate information with > > the User-Name AVP sent in the MAR-command. > > > > It seems the case where Diameter server sends HA1 in MAA > > and client calculates and checks the response has not been > > taken into account when the required contents of SIP-Authorization, > > SIP-Authenticate, and SIP-Authentication-Info AVP have been defined. > > > > It is not clear what is included to MAA message in case > > Diameter server has checked the response successfully. > > It might be useful if the Diameter client receives a confirmation > > of the auth-scheme applied by the Diameter-server. > > > > > > Requested changes: > > > > 1. Remove SIP-Method AVP from the spec > > 2. Remove Digest-Username from the spec. (If needed add text where > > it is explained that Digest-Username is translated to > > User-Name in the case of Radius-Diameter translation.) > > 3. Change Digest-Nonce to optional in SIP-Authenticate > > 4. Change the following AVPs to optional in SIP-Authorization AVP: > > Digest-Nonce, Digest-URI, Digest-Response > > 5. Change Digest-Nextnonce to optional in > SIP-Authentication-Info AVP > > 6. After Diameter server has checked that the response is ok > > it returns MAA where result-code is SUCCESS, and > SIP-Auth-Data-Item > > with the SIP-Authentication-Scheme AVP. > > > > 7. Change the following text in Section 7.8: > > If the SIP-Methods AVP value of the Diameter MAR message > is set to > > REGISTER and a User-Name AVP is present, then the Diameter server > > MUST authorize that User-Name AVP value is able to use the URI > > included in the SIP-AOR AVP. If this authorization fails, the > > Diameter server must set the Result-Code AVP to > > DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter > > Multimedia-Auth-Answer (MAA) message. > > To: > > If the Digest-Method AVP value is either absent or > received with a > > value REGISTER in the Diameter MAR message and a User-Name AVP is > > present, then the Diameter server MUST authorize that > User-Name AVP > > value is able to use the URI included in the SIP-AOR > AVP. If this > > authorization fails, the Diameter server must set the > Result-Code AVP to > > DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter > > Multimedia-Auth-Answer (MAA) message. > > > > > > BR, > > Mikko > > > > > > PS. Sorry for the late submission.. > > > > -- > Miguel A. Garcia tel:+358-50-4804586 > sip:[email protected] > Nokia Research Center Helsinki, Finland > >