Re: : ISSUE, SIP, Duplicate user-name
Miguel Garcia <[email protected]> Thu, 27 Oct 2005 15:31:02 +0300
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
The need to have a duplication is to have a smooth and easy transition from RADIUS to Diameter, because the RADIUS document already specifies Digest-Username. Adding an AVP for consistency and smooth transition is considered more elegant than trying to save a few bytes here. As far as I know, we don't have any requirement that puts constraints on the number of bytes transferred. /Miguel [email protected] wrote: > Hi! > > I agree with everything you said about the usage of > User-Name AVP. > > But my issue was: why is there need for the Digest-Username AVP in > the Diameter SIP Application? It is enough to have User-Name AVP. > > When Digest is used the SIP-server fills User-Name AVP from the > username contained in Authorization header. > > When Digest is used the SIP-server fills Digest-Username AVP from > the username contained in Authorization header. > > Why is there need to transport this information once in > the SIP-message, but twice in the Diameter message? > It is redundant information. > > Conclusion: Digest-Username AVP is not needed in > Diameter SIP Application. Let's get rid of it. > > > BR, > Mikko > > > >>-----Original Message----- >>From: Miguel Garcia [mailto:[email protected]] >>Sent: 27 October, 2005 13:32 >>To: Aittola Mikko (Nokia-NET/Tampere) >>Cc: [email protected] >>Subject: Re: [AAA-WG]: ISSUE, SIP, Duplicate user-name >> >> >>This issue was discussed in the past and agreed as it is >>today. The main >>point is that Digest-Username assumes that you are using Digest >>authentication and there is a username already present in the Digest >>information. However, we may have other non-Digest authentication >>mechanisms in the future. In order to provide a smooth transition, we >>need to have a username in order to identify the user in the >>database, >>independent of the authentication mechanism. >> >>To be more explicit: >> >>User-Name is used for authorizing a registration and >>identifying a user >>data in a database, even when there is no digest authentication (and >>thus no Digest-Username AVP). >> >>Section 7.2 has procedures for the User-Name AVP: >> >>If a User-Name AVP is present in the Diameter UAR message, then the >>Diameter server MUST authorize that User-Name AVP value is able to >>register the SIP or SIPS URI included in the SIP-AOR AVP. If this >>authorization fails, the Diameter server must set the >>Result-Code AVP to >>DIAMETER_ERROR_IDENTITIES_DONT_MATCH and send it in a Diameter >>User-Authorization-Answer (UAA) message. >> >> Correlation between User-Name and SIP-AOR AVP values is >>required in order to avoid registration of a SIP-AOR allocated to >>another user. >> >> >>Then later in Section 7.7 the text reads: >> >>If the SIP request includes some sort of authentication >>information, the >>Diameter client MUST include the user name, extracted from the >>authentication information of the SIP request, in the >>User-Name AVP value. >> >>Note that the text is not Digest specific. >> >> >>So I am afraid I can't agree with this issue. >> >>/Miguel >> >>[email protected] wrote: >> >> >>>Description of issue: Duplicate user-name >>>Submitter name: Mikko Aittola >>>Submitter email address: [email protected] >>>Date first submitted: 26 Oct 05 >>>Document: sip (v. 10) >>>Comment type: T >>>Priority: S >>>Section: 8.5.4 >>>Rationale/Explanation of issue: >>> >>>SIP-Authorization grouped AVP contains required AVP >>>Digest-Username. This is duplicate information with >>>the User-Name AVP sent in the MAR-command. >>> >>> >>>Rquested changes: >>> >>>Remove Digest-Username from SIP-Authorization AVP. If needed >>>add text where it is explained that Digest-Username is translated >>>to User-Name in the case of Radius-Diameter translation. >>> >>> >>>BR, >>>Mikko >>> >> >>-- >>Miguel A. Garcia tel:+358-50-4804586 >>sip:[email protected] >>Nokia Research Center Helsinki, Finland >> >> > > -- Miguel A. Garcia tel:+358-50-4804586 sip:[email protected] Nokia Research Center Helsinki, Finland