2009/7/29 Iñaki Baz Castillo <i...@aliax.net>: > > However, it'd also work even if the client uses a different > call-id/from-tag in the second INVITE (with credentials). For example, > a proxy doesn't store the "failed dialog status" so when receives an > INVITE with credentials it doesn't check call-id/from-tag values > against a previous attemp.
Not entirely. It is reasonable for a proxy/UAS to create nonces statelessly based on call-id/from-tag. The second INVITE would need to reuse the call-id/from-tag so that the nonce could be checked and found valid before the hash is checked. Regards, Michael _______________________________________________ Sip-implementors mailing list Sip-implementors@lists.cs.columbia.edu https://lists.cs.columbia.edu/cucslists/listinfo/sip-implementors