: why is Digest-Nextnonce mandatory ?
"Jo Hermans" <[email protected]> Tue, 6 Jun 2006 16:42:27 +0200
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
I have a problem with the Digest-Nextnonce parameter in the
Sip-Authentication-Info attribute in the MAA, which becomes the
AuthenticationInfo header in the 200 OK of SIP. We've recently seen an
issue with Nokia terminals that are insisting that this is a mandatory
parameter (according to draft-ietf-aaa-diameter-sip-app-12.txt, but
originating from RFC2617 section 3.2.3). Our code is more based on
draft-ietf-radext-digest-auth-09.txt, where it is optional.
I agree that those Nokia terminals are according to the spec, but I
have to deal with our HSS that does not want to send back a nextnonce,
mostly out of fear of the remark in RFC2617 section 3.2.2 (about
problems in pipelining requests). At the same time, those people
insist on having mutual authentication between client and server, so
we need to Authentication-Info header in the 200 OK. Because the
nextnonce is mandatory, we can't send that header at all. I'm stuck
between a rock and a hard place at the moment. I now have to make the
decision to either remove the entire header (removing mutual
authentication), or adding a dummy nextnonce (which will cause a 401
later on).
I want to know if there's a reason why the nextnonce is mandatory in
the spec. Is it only RFC2617 ? As far as I can see (changes from
RFC2069), it looks like a typo to me, and it should be optional. If it
was really mandatory, the next paragraph would have been changed too
("if the nextnonce field is present ..."). And you still have the
problem with the pipelining (we've already encountered them, for
instance in a phone that send 2 INVITE's in parallel, in order to set
up a conference).
I know it's very late, and Last-Call of
draft-ietf-aaa-diameter-sip-app is already past. But INHO,
Digest-Nextnonce should be an optional parameter, so that
Authentication-Info can be used for mutual authentication, without a
Next-Nonce. RFC2617 is probably incorrect, and conflicts with RFC3261
anyway. What's your opinion ?
The issue has been mentioned in :
- http://www1.ietf.org/mail-archive/web/sipping/current/msg08387.html
(no response)
- http://danforsberg.info:8080/draft-ietf-aaa-diameter-sip/issue45
(rejected by Miguel, but he answered me that it's possibly wrong)
--
Jo Hermans
"Eagles may soar, but weasels aren't sucked into jet engines"