At 05:43 PM 7/25/2002, Shan Lu wrote: >>-----Original Message----- >>From: Jiri Kuthan [mailto:[EMAIL PROTECTED]] >>Sent: Thursday, July 25, 2002 10:33 AM >>To: Shan Lu; 'James Undery'; [EMAIL PROTECTED] >>Cc: [EMAIL PROTECTED] >>Subject: RE: [Sip] Authentication and ACK >> >> >> >>If you are interested in security, you better go for secure transport. >>I do not see any great security benefit in copy'n'paste of INVITE's >>credentials. >> > >Are you saying the proxy should just proxy along any ACK?
Yes. >>Note that none of these issues is related to whether a server >>is stateful or stateless. >> > >Why can't a stateful proxy correlate ACK with INVITE and find out >whether the INVITE is being challenged and handle ACK accordingly? Remembering whether an INVITE was authenticated properly does not gain you knowledge that ACK is coming from the same person -- the ACK is a brand-new message which might have been sent by anyone else in posession of IP access. -Jiri _______________________________________________ Sip-implementors mailing list [EMAIL PROTECTED] http://lists.cs.columbia.edu/mailman/listinfo/sip-implementors
