Hi,

RFC 3261 section 26.3.2.4 provides additional recommendations concerning 401 
and 407.

"UAs and proxy servers SHOULD challenge questionable requests with
 only a single 401 (Unauthorized) or 407 (Proxy Authentication
 Required), forgoing the normal response retransmission algorithm, and
 thus behaving statelessly towards unauthenticated requests.

    Retransmitting the 401 (Unauthorized) or 407 (Proxy Authentication
    Required) status response amplifies the problem of an attacker
    using a falsified header field value (such as Via) to direct
    traffic to a third party."

> -----Original Message-----
> From: ankur bansal [mailto:abh.an...@gmail.com]
> Sent: Monday, December 30, 2013 3:25 AM
> To: Aditya Kumar
> Cc: sip-implementors@lists.cs.columbia.edu
> Subject: Re: [Sip-implementors] ACK timeout
> 
> Hi Aditya
> 
> Please go through Section 17.2.1 INVITE Server Transaction of RFC 3261
> 
> In brief , UE(trxn layer) should retransmit final response till Timer
> H(64
> * T1) fires .and if still ACK not came ,transaction will move to
> terminated
> state .
> 
> Thanks & regards
> Ankur Bansal
> 
> 
> On Sun, Dec 29, 2013 at 9:49 PM, Aditya Kumar
> <adityakumar...@yahoo.com>wrote:
> 
> > Hi,
> > UE Receives INVITE.
> > sends 486 //Any Failure 3xx,4xx,5xx,6xx
> > ACK is lost.
> >
> > what should be the behavior.
> > I mean for how much time should the UE keep the transaction state?
> > or wil do that clean up immediately?


_______________________________________________
Sip-implementors mailing list
Sip-implementors@lists.cs.columbia.edu
https://lists.cs.columbia.edu/cucslists/listinfo/sip-implementors

Reply via email to