AW: : Diameter SIP app: Issue 59
"Beck01, Wolfgang" <[email protected]> Thu, 26 Jan 2006 18:36:05 +0100
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
> We had already some comments from Sam Hartman about the issue of the > dependency on MD5. > > http://danforsberg.info:8080/draft-ietf-aaa-diameter-sip/issue59 > Digest-HA1 is not an optimization, but a way to generate an Authentication-Info header without sending the password to the SIP server. While we are at it, in the radext draft's IESG review, there were concerns about replayed nonces, when the SIP server generates nonces and gets hijacked. There are two options - Ignore this complaint, if the SIP server gets hijacked the attacker can access the service without bothering about a AAA server. - Define a nonce format between AAA client and server, that includes an integrity-protected time-stamp. The server rejects nonces that are too old. But the AAA client's clock will differ from the server's.. Wolfgang -- T-Systems Next Generation IP Services and Systems +49 6151 937 2863 Am Kavalleriesand 3 64295 Darmstadt Germany