Re: : ISSUE, SIP, authentication parameters
Miguel Garcia <[email protected]> Tue, 25 Oct 2005 17:06:00 +0300
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Inline discussion. [email protected] wrote: > >>and we wanted to add a possibility to enable the scenario >>described in Sections 5.5 and 5.6, where an outbound proxy is >>authorizing request. Some users might be authorized to use any >>SIP method, others only a few of them. In order to do this, >>the SIP-Method must be present. > > > I think in order to do that it's enough to define that the default-behavior > of Diameter server is that all SIP-methods are authorized. This is applied > in the case where no Digest-Method is received. If the Diameter server receives > Digest-Method then it can apply some other policy. This is what the text > I proposed does. So there is no need to have SIP-Method as required > AVP. > No, it is just simpler to have a specific AVP (SIP-Method) that indicates the method of the SIP request that is under authorization. Clear semantics of what is the purpose of this AVP. > > >>And at that point in time, the user might not have sent any >>Authorization header, so the Digest-Method might not be present. > > > The Diameter client can fill the Digest-Method to the SIP-Authorization > AVP even if there is no Authorization header in the SIP-request. > > What about the other problems I indicated in the issue? What you are proposing is a fake of the whole authorization mechanism specified in RFC 2617. An Authorization header should contain a number of directives, such as username, realm, nonce, digest-uri, and response, which happen that none of them are present in the SIP INVITE request. I am sorry, but the current text is technically correct. If you find a defect we can discuss it, but I am saying that there is not such defect. Ah, are there any other problems in the issue? I thought one issue equals one problem... /Miguel > > > BR, > Mikko > > > >>-----Original Message----- >>From: Miguel Garcia [mailto:[email protected]] >>Sent: 25 October, 2005 15:55 >>To: Aittola Mikko (Nokia-NET/Tampere) >>Cc: [email protected] >>Subject: Re: [AAA-WG]: ISSUE, SIP, authentication parameters >> >> >>Hi: >> >>First I am sorry to say that the time for the 3rd WGLC is over, so we >>are not ready to make changes during this process. We can do changes >>during the IETF Last call, if those changes are justified. >> >>With respect your comment. We discussed this issue about 2 years ago, >>and we wanted to add a possibility to enable the scenario >>described in >>Sections 5.5 and 5.6, where an outbound proxy is authorizing request. >>Some users might be authorized to use any SIP method, others >>only a few >>of them. In order to do this, the SIP-Method must be present. And at >>that point in time, the user might not have sent any Authorization >>header, so the Digest-Method might not be present. >> >>Sorry, but NO. >> >>/Miguel >> >>[email protected] wrote: >> >> >>>Description of issue: Authentication parameters >>>Submitter name: Mikko Aittola >>>Submitter email address: [email protected] >>>Date first submitted: 25 Oct 05 >>>Document: sip (v. 10) >>>Comment type: T >>>Priority: S >>>Sections: 7.7, 7.8, 8.5.3, 8.5.4, 8.5.5 >>>Rationale/Explanation of issue: >>> >>>SIP-Method is defined to be required AVP in MAR-command. >>>Is there really need for this to be required AVP? >>>I think Diameter server doesn't necessarily need to consider >>>what is the SIP-method the SIP-server is asking to authenticate. >>> >>>Furthermore, there is already optional Digest-Method AVP >>>in SIP-Authorization grouped AVP. This can be used for >>>the same purpose as SIP-Method AVP. >>> >>>SIP-Authorization grouped AVP contains required AVP >>>Digest-Username. This is duplicate information with >>>the User-Name AVP sent in the MAR-command. >>> >>>It seems the case where Diameter server sends HA1 in MAA >>>and client calculates and checks the response has not been >>>taken into account when the required contents of SIP-Authorization, >>>SIP-Authenticate, and SIP-Authentication-Info AVP have been defined. >>> >>>It is not clear what is included to MAA message in case >>>Diameter server has checked the response successfully. >>>It might be useful if the Diameter client receives a confirmation >>>of the auth-scheme applied by the Diameter-server. >>> >>> >>>Requested changes: >>> >>>1. Remove SIP-Method AVP from the spec >>>2. Remove Digest-Username from the spec. (If needed add text where >>> it is explained that Digest-Username is translated to >>> User-Name in the case of Radius-Diameter translation.) >>>3. Change Digest-Nonce to optional in SIP-Authenticate >>>4. Change the following AVPs to optional in SIP-Authorization AVP: >>> Digest-Nonce, Digest-URI, Digest-Response >>>5. Change Digest-Nextnonce to optional in >> >>SIP-Authentication-Info AVP >> >>>6. After Diameter server has checked that the response is ok >>> it returns MAA where result-code is SUCCESS, and >> >>SIP-Auth-Data-Item >> >>> with the SIP-Authentication-Scheme AVP. >>> >>>7. Change the following text in Section 7.8: >>> If the SIP-Methods AVP value of the Diameter MAR message >> >>is set to >> >>> REGISTER and a User-Name AVP is present, then the Diameter server >>> MUST authorize that User-Name AVP value is able to use the URI >>> included in the SIP-AOR AVP. If this authorization fails, the >>> Diameter server must set the Result-Code AVP to >>> DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter >>> Multimedia-Auth-Answer (MAA) message. >>> To: >>> If the Digest-Method AVP value is either absent or >> >>received with a >> >>> value REGISTER in the Diameter MAR message and a User-Name AVP is >>> present, then the Diameter server MUST authorize that >> >>User-Name AVP >> >>> value is able to use the URI included in the SIP-AOR >> >>AVP. If this >> >>> authorization fails, the Diameter server must set the >> >>Result-Code AVP to >> >>> DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter >>> Multimedia-Auth-Answer (MAA) message. >>> >>> >>>BR, >>>Mikko >>> >>> >>>PS. Sorry for the late submission.. >>> >> >>-- >>Miguel A. Garcia tel:+358-50-4804586 >>sip:[email protected] >>Nokia Research Center Helsinki, Finland >> >> > > -- Miguel A. Garcia tel:+358-50-4804586 sip:[email protected] Nokia Research Center Helsinki, Finland