RE: : ISSUE, SIP, Duplicate user-name

<[email protected]> Thu, 27 Oct 2005 14:12:19 +0300
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
Hi!

I agree with everything you said about the usage of
User-Name AVP.

But my issue was: why is there need for the Digest-Username AVP in
the Diameter SIP Application? It is enough to have User-Name AVP.

When Digest is used the SIP-server fills User-Name AVP from the
username contained in Authorization header.

When Digest is used the SIP-server fills Digest-Username AVP from
the username contained in Authorization header.

Why is there need to transport this information once in
the SIP-message, but twice in the Diameter message?
It is redundant information.

Conclusion: Digest-Username AVP is not needed in
Diameter SIP Application. Let's get rid of it.


BR,
Mikko


> -----Original Message-----
> From: Miguel Garcia [mailto:[email protected]]
> Sent: 27 October, 2005 13:32
> To: Aittola Mikko (Nokia-NET/Tampere)
> Cc: [email protected]
> Subject: Re: [AAA-WG]: ISSUE, SIP, Duplicate user-name
> 
> 
> This issue was discussed in the past and agreed as it is 
> today. The main 
> point is that Digest-Username assumes that you are using Digest 
> authentication and there is a username already present in the Digest 
> information. However, we may have other non-Digest authentication 
> mechanisms in the future. In order to provide a smooth transition, we 
> need to have a username in order to identify the user in the 
> database, 
> independent of the authentication mechanism.
> 
> To be more explicit:
> 
> User-Name is used for authorizing a registration and 
> identifying a user 
> data in a database, even when there is no digest authentication (and 
> thus no Digest-Username AVP).
> 
> Section 7.2 has procedures for the User-Name AVP:
> 
> If a User-Name AVP is present in the Diameter UAR message, then the 
> Diameter server MUST authorize that User-Name AVP value is able to 
> register the SIP or SIPS URI included in the SIP-AOR AVP. If this 
> authorization fails, the Diameter server must set the 
> Result-Code AVP to 
> DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter 
> User-Authorization-Answer (UAA) message.
> 
>          Correlation between User-Name and SIP-AOR AVP values is 
> required in order to avoid registration of a SIP-AOR allocated to 
> another user.
> 
> 
> Then later in Section 7.7 the text reads:
> 
> If the SIP request includes some sort of authentication 
> information, the 
> Diameter client MUST include the user name, extracted from the 
> authentication information of the SIP request, in the 
> User-Name AVP value.
> 
> Note that the text is not Digest specific.
> 
> 
> So I am afraid I can't agree with this issue.
> 
> /Miguel
> 
> [email protected] wrote:
> 
> > Description of issue: Duplicate user-name
> > Submitter name: Mikko Aittola
> > Submitter email address: [email protected]
> > Date first submitted: 26 Oct 05
> > Document: sip (v. 10)
> > Comment type: T
> > Priority: S
> > Section: 8.5.4
> > Rationale/Explanation of issue:
> > 
> > SIP-Authorization grouped AVP contains required AVP
> > Digest-Username. This is duplicate information with
> > the User-Name AVP sent in the MAR-command.
> > 
> > 
> > Rquested changes:
> > 
> > Remove Digest-Username from SIP-Authorization AVP. If needed
> > add text where it is explained that Digest-Username is translated
> > to User-Name in the case of Radius-Diameter translation.
> > 
> > 
> > BR,
> > Mikko
> > 
> 
> -- 
> Miguel A. Garcia           tel:+358-50-4804586
> sip:[email protected]
> Nokia Research Center      Helsinki, Finland
> 
>