Re: : ISSUE, SIP, authentication parameters

Miguel Garcia <[email protected]> Tue, 25 Oct 2005 17:06:00 +0300
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Inline discussion.

[email protected] wrote:

> 
>>and we wanted to add a possibility to enable the scenario 
>>described in Sections 5.5 and 5.6, where an outbound proxy is
>>authorizing request. Some users might be authorized to use any
>>SIP method, others only a few of them. In order to do this,
>>the SIP-Method must be present.
> 
> 
> I think in order to do that it's enough to define that the default-behavior
> of Diameter server is that all SIP-methods are authorized. This is applied
> in the case where no Digest-Method is received. If the Diameter server receives
> Digest-Method then it can apply some other policy. This is what the text
> I proposed does. So there is no need to have SIP-Method as required
> AVP.
> 

No, it is just simpler to have a specific AVP (SIP-Method) that 
indicates the method of the SIP request that is under authorization. 
Clear semantics of what is the purpose of this AVP.

> 
> 
>>And at that point in time, the user might not have sent any
>>Authorization header, so the Digest-Method might not be present.
> 
> 
> The Diameter client can fill the Digest-Method to the SIP-Authorization
> AVP even if there is no Authorization header in the SIP-request.
> 
> What about the other problems I indicated in the issue?

What you are proposing is a fake of the whole authorization mechanism 
specified in RFC 2617. An Authorization header should contain a number 
of directives, such as username, realm, nonce, digest-uri, and response, 
which happen that none of them are present in the SIP INVITE request.

I am sorry, but the current text is technically correct. If you find a 
defect we can discuss it, but I am saying that there is not such defect.

Ah, are there any other problems in the issue? I thought one issue 
equals one problem...

/Miguel

> 
> 
> BR,
> Mikko
> 
> 
> 
>>-----Original Message-----
>>From: Miguel Garcia [mailto:[email protected]]
>>Sent: 25 October, 2005 15:55
>>To: Aittola Mikko (Nokia-NET/Tampere)
>>Cc: [email protected]
>>Subject: Re: [AAA-WG]: ISSUE, SIP, authentication parameters
>>
>>
>>Hi:
>>
>>First I am sorry to say that the time for the 3rd WGLC is over, so we 
>>are not ready to make changes during this process. We can do changes 
>>during the IETF Last call, if those changes are justified.
>>
>>With respect your comment. We discussed this issue about 2 years ago, 
>>and we wanted to add a possibility to enable the scenario 
>>described in 
>>Sections 5.5 and 5.6, where an outbound proxy is authorizing request. 
>>Some users might be authorized to use any SIP method, others 
>>only a few 
>>of them. In order to do this, the SIP-Method must be present. And at 
>>that point in time, the user might not have sent any Authorization 
>>header, so the Digest-Method might not be present.
>>
>>Sorry, but NO.
>>
>>/Miguel
>>
>>[email protected] wrote:
>>
>>
>>>Description of issue: Authentication parameters
>>>Submitter name: Mikko Aittola
>>>Submitter email address: [email protected]
>>>Date first submitted: 25 Oct 05
>>>Document: sip (v. 10)
>>>Comment type: T
>>>Priority: S
>>>Sections: 7.7, 7.8, 8.5.3, 8.5.4, 8.5.5
>>>Rationale/Explanation of issue:
>>>
>>>SIP-Method is defined to be required AVP in MAR-command.
>>>Is there really need for this to be required AVP?
>>>I think Diameter server doesn't necessarily need to consider
>>>what is the SIP-method the SIP-server is asking to authenticate.
>>>
>>>Furthermore, there is already optional Digest-Method AVP
>>>in SIP-Authorization grouped AVP. This can be used for
>>>the same purpose as SIP-Method AVP.
>>>
>>>SIP-Authorization grouped AVP contains required AVP
>>>Digest-Username. This is duplicate information with
>>>the User-Name AVP sent in the MAR-command.
>>>
>>>It seems the case where Diameter server sends HA1 in MAA
>>>and client calculates and checks the response has not been
>>>taken into account when the required contents of SIP-Authorization,
>>>SIP-Authenticate, and SIP-Authentication-Info AVP have been defined.
>>>
>>>It is not clear what is included to MAA message in case
>>>Diameter server has checked the response successfully.
>>>It might be useful if the Diameter client receives a confirmation
>>>of the auth-scheme applied by the Diameter-server.
>>>
>>>
>>>Requested changes:
>>>
>>>1. Remove SIP-Method AVP from the spec
>>>2. Remove Digest-Username from the spec. (If needed add text where
>>>   it is explained that Digest-Username is translated to
>>>   User-Name in the case of Radius-Diameter translation.)
>>>3. Change Digest-Nonce to optional in SIP-Authenticate
>>>4. Change the following AVPs to optional in SIP-Authorization AVP:
>>>   Digest-Nonce, Digest-URI, Digest-Response
>>>5. Change Digest-Nextnonce to optional in 
>>
>>SIP-Authentication-Info AVP
>>
>>>6. After Diameter server has checked that the response is ok
>>>   it returns MAA where result-code is SUCCESS, and 
>>
>>SIP-Auth-Data-Item
>>
>>>   with the SIP-Authentication-Scheme AVP.
>>>
>>>7. Change the following text in Section 7.8:
>>>   If the SIP-Methods AVP value of the Diameter MAR message 
>>
>>is set to
>>
>>>   REGISTER and a User-Name AVP is present, then the Diameter server
>>>   MUST authorize that User-Name AVP value is able to use the URI
>>>   included in the SIP-AOR AVP.  If this authorization fails, the
>>>   Diameter server must set the Result-Code AVP to
>>>   DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter
>>>   Multimedia-Auth-Answer (MAA) message.
>>> To:
>>>   If the Digest-Method AVP value is either absent or 
>>
>>received with a
>>
>>>   value REGISTER in the Diameter MAR message and a User-Name AVP is
>>>   present, then the Diameter server MUST authorize that 
>>
>>User-Name AVP
>>
>>>   value is able to use the URI included in the SIP-AOR 
>>
>>AVP.  If this
>>
>>>   authorization fails, the Diameter server must set the 
>>
>>Result-Code AVP to
>>
>>>   DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter
>>>   Multimedia-Auth-Answer (MAA) message.
>>>
>>>
>>>BR,
>>>Mikko
>>>
>>>
>>>PS. Sorry for the late submission..
>>>
>>
>>-- 
>>Miguel A. Garcia           tel:+358-50-4804586
>>sip:[email protected]
>>Nokia Research Center      Helsinki, Finland
>>
>>
> 
> 

-- 
Miguel A. Garcia           tel:+358-50-4804586
sip:[email protected]
Nokia Research Center      Helsinki, Finland