: [DSA]: Generation of nonces
Miguel Garcia <[email protected]> Fri, 10 Mar 2006 15:21:58 +0200
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
As you may know, the Diameter SIP application is under IESG review. There have been some comments that you can follow in the data tracker: https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=10945&rfc_flag=0 The important comment is originated by the Security ADs: there is an issue with the generation of nonces in the client. The issue was first identified in the RADIUS extension for HTTP/SIP authentication, and the resolution should be unique for both RADIUS and Diameter. The exact issue is recorded here: https://datatracker.ietf.org/public/pidtracker.cgi?command=view_comment&id=43578 The RADIUS draft was re-issued recently, and already tried to address this issue by providing an known algorithm for creating and verifying nonces. This hasn't been revised by the Security ADs yet, so it is unknown at this stage if this clears that discuss or not. But just in case it clears it, we may need to add similar wording to the Diameter SIP application. So, I would like that the AAA group reviews a couple of sections of the RADIUS Digest draft to find out if we are ok with the nonce generation guidelines. If we find no objections and if this is ok to the Security ADs, we will add it to the Diameter document. The latest version of the RADIUS Digest draft is: http://www.ietf.org/internet-drafts/draft-ietf-radext-digest-auth-07.txt Sections that are relevant for the nonce generation in the client are 3.2.5 and 3.3.2. Please, comment and speak if you have problems. Copy Wolfgang in the discussion. /Miguel -- Miguel A. Garcia tel:+358-50-4804586 sip:[email protected] Nokia Research Center Helsinki, Finland