RE: : ISSUE, SIP, Required authentication AVPs

<[email protected]> Thu, 27 Oct 2005 13:37:26 +0300
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hi!

> Then an INVITE (3) is received with the credentials. The
> Diameter client takes all of them, included the generated nonce, and
> pass them to the Diameter server in a MAR request (particularly in a
> SIP-Authenticate AVP). The Diameter server may need the nonce to 
> generate H(A1).

I think in the MAR request the AVP that is sent in this case
is the SIP-Authorization AVP. So I still think that in
SIP-Authenticate there is no need for the Digest-Nonce to be
required AVP.


BR,
Mikko


> -----Original Message-----
> From: Miguel Garcia [mailto:[email protected]]
> Sent: 27 October, 2005 13:04
> To: Aittola Mikko (Nokia-NET/Tampere)
> Cc: [email protected]
> Subject: Re: [AAA-WG]: ISSUE, SIP, Required authentication AVPs
> 
> 
> Hi.
> 
> So if I understand correctly, you are describing the case when:
> - Nonces are generated in the Diameter client
> - Check for final authentication also takes place in the 
> Diameter client.
> 
> If that is correct, then we are looking at a flow similar to Figure 5.
> 
> Under Figure 5, the SIP server receives an INVITE (1), 
> generates a nonce
> and the rest of the parameters of the challenge, and sends 
> them back in
> a 407 (2). Then an INVITE (3) is received with the credentials. The
> Diameter client takes all of them, included the generated nonce, and
> pass them to the Diameter server in a MAR request (particularly in a
> SIP-Authenticate AVP). The Diameter server may need the nonce to 
> generate H(A1).
> 
> Thus, I think the SIP-Authenticate AVP MUST contain a nonce, thus, I
> don't agree with your point 1 below.
> 
> Then the Diameter server does the stuff it has to do, and 
> generates the
> MAA containing a SIP-Authorization AVP. Digest-Nonce is valid and know
> by the Diameter server (it was sent by the client), so we can make it
> optional or leave it as is.
> 
> The Diameter server calculatest H(A1) and returns it to the Diameter 
> Client in a MAA command. I agree with fact that the Diameter 
> server does 
> not need to know the Digest-URI or the Digest-Response. So I agree on 
> making them optional in the SIP-Authorization AVP.
> 
> I also agree that Digest-Nextnonce should be optional in 
> SIP-Authentication-Info.
> 
> So, in summary. As for your points:
> 
>  > 1. Change Digest-Nonce to optional in SIP-Authenticate
> I don't agree.
> 
>  > 2. Change the following AVPs to optional in SIP-Authorization AVP:
>  >    Digest-Nonce, Digest-URI, and Digest-Response
> I agree.
> 
>  > 3. Change Digest-Nextnonce to optional in 
> SIP-Authentication-Info AVP
> I agree.
> 
> Is this ok, or have I missed something with respect your first point?
> 
> /Miguel
> 
> [email protected] wrote:
> 
> > Description of issue: Authentication parameters
> > Submitter name: Mikko Aittola
> > Submitter email address: [email protected]
> > Date first submitted: 26 Oct 05
> > Document: sip (v. 10)
> > Comment type: T
> > Priority: S
> > Sections: 8.5.3, 8.5.4, 8.5.5
> > 
> > It seems the case where Diameter server sends HA1 in MAA
> > and client generates nonce, and where client calculates and
> > checks the response has not been taken into account when the
> > required contents of SIP-Authorization, SIP-Authenticate, and
> > SIP-Authentication-Info AVP have been defined.
> > 
> > 
> > Requested changes:
> > 
> > 1. Change Digest-Nonce to optional in SIP-Authenticate
> > 2. Change the following AVPs to optional in SIP-Authorization AVP:
> >    Digest-Nonce, Digest-URI, and Digest-Response
> > 3. Change Digest-Nextnonce to optional in 
> SIP-Authentication-Info AVP
> > 
> > 
> > BR,
> > Mikko
> > 
> 
> -- 
> Miguel A. Garcia           tel:+358-50-4804586
> sip:[email protected]
> Nokia Research Center      Helsinki, Finland
> 
> 
> 
>