AW: : Diameter SIP app: Issue 59

"Beck01, Wolfgang" <[email protected]> Thu, 26 Jan 2006 18:36:05 +0100
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>

> We had already some comments from Sam Hartman about the issue of the 
> dependency on MD5.
> 
> http://danforsberg.info:8080/draft-ietf-aaa-diameter-sip/issue59
> 
Digest-HA1 is not an optimization, but a way to generate an Authentication-Info
header without sending the password to the SIP server.

While we are at it, in the radext draft's IESG review, there were concerns
about replayed nonces, when the SIP server generates nonces and gets hijacked.
There are two options

- Ignore this complaint, if the SIP server gets hijacked the attacker
can access the service without bothering about a AAA server.

- Define a nonce format between AAA client and server, that includes
an integrity-protected time-stamp. The server rejects nonces that are
too old. But the AAA client's clock will differ from the server's..



Wolfgang

--
T-Systems
Next Generation IP Services and Systems
+49 6151 937 2863
Am Kavalleriesand 3
64295 Darmstadt
Germany