RE: : ISSUE, SIP, Required authentication AVPs
<[email protected]> Thu, 27 Oct 2005 13:37:26 +0300
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Hi! > Then an INVITE (3) is received with the credentials. The > Diameter client takes all of them, included the generated nonce, and > pass them to the Diameter server in a MAR request (particularly in a > SIP-Authenticate AVP). The Diameter server may need the nonce to > generate H(A1). I think in the MAR request the AVP that is sent in this case is the SIP-Authorization AVP. So I still think that in SIP-Authenticate there is no need for the Digest-Nonce to be required AVP. BR, Mikko > -----Original Message----- > From: Miguel Garcia [mailto:[email protected]] > Sent: 27 October, 2005 13:04 > To: Aittola Mikko (Nokia-NET/Tampere) > Cc: [email protected] > Subject: Re: [AAA-WG]: ISSUE, SIP, Required authentication AVPs > > > Hi. > > So if I understand correctly, you are describing the case when: > - Nonces are generated in the Diameter client > - Check for final authentication also takes place in the > Diameter client. > > If that is correct, then we are looking at a flow similar to Figure 5. > > Under Figure 5, the SIP server receives an INVITE (1), > generates a nonce > and the rest of the parameters of the challenge, and sends > them back in > a 407 (2). Then an INVITE (3) is received with the credentials. The > Diameter client takes all of them, included the generated nonce, and > pass them to the Diameter server in a MAR request (particularly in a > SIP-Authenticate AVP). The Diameter server may need the nonce to > generate H(A1). > > Thus, I think the SIP-Authenticate AVP MUST contain a nonce, thus, I > don't agree with your point 1 below. > > Then the Diameter server does the stuff it has to do, and > generates the > MAA containing a SIP-Authorization AVP. Digest-Nonce is valid and know > by the Diameter server (it was sent by the client), so we can make it > optional or leave it as is. > > The Diameter server calculatest H(A1) and returns it to the Diameter > Client in a MAA command. I agree with fact that the Diameter > server does > not need to know the Digest-URI or the Digest-Response. So I agree on > making them optional in the SIP-Authorization AVP. > > I also agree that Digest-Nextnonce should be optional in > SIP-Authentication-Info. > > So, in summary. As for your points: > > > 1. Change Digest-Nonce to optional in SIP-Authenticate > I don't agree. > > > 2. Change the following AVPs to optional in SIP-Authorization AVP: > > Digest-Nonce, Digest-URI, and Digest-Response > I agree. > > > 3. Change Digest-Nextnonce to optional in > SIP-Authentication-Info AVP > I agree. > > Is this ok, or have I missed something with respect your first point? > > /Miguel > > [email protected] wrote: > > > Description of issue: Authentication parameters > > Submitter name: Mikko Aittola > > Submitter email address: [email protected] > > Date first submitted: 26 Oct 05 > > Document: sip (v. 10) > > Comment type: T > > Priority: S > > Sections: 8.5.3, 8.5.4, 8.5.5 > > > > It seems the case where Diameter server sends HA1 in MAA > > and client generates nonce, and where client calculates and > > checks the response has not been taken into account when the > > required contents of SIP-Authorization, SIP-Authenticate, and > > SIP-Authentication-Info AVP have been defined. > > > > > > Requested changes: > > > > 1. Change Digest-Nonce to optional in SIP-Authenticate > > 2. Change the following AVPs to optional in SIP-Authorization AVP: > > Digest-Nonce, Digest-URI, and Digest-Response > > 3. Change Digest-Nextnonce to optional in > SIP-Authentication-Info AVP > > > > > > BR, > > Mikko > > > > -- > Miguel A. Garcia tel:+358-50-4804586 > sip:[email protected] > Nokia Research Center Helsinki, Finland > > > >