> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of
> Michael Thomas
> >
> Therein lies the conundrum with intermediate manglers like B2BUA's
> and mailing lists managers, etc. On the one hand, you can sign very little
> and be far more successful at surviving the mangler. However, that's
> buying
> you very, very little since things that the manglers mangle are the very
> things
> that you want to protect. So why bother.

So the question is: what is it that you really want to protect?  Is it 
literally the To/From/Call-id/etc. headers; or is it the source AoR, target 
AoR, and some additional info to prevent replay?

My belief is the latter.  Using the To/From/Call-id/etc. in 4474 was 
essentially a convenience, because the assumption was the info is already in 
those headers so one might as well reuse them for 4474's purpose.  But for some 
deployment scenarios those headers get changed - not because the changers 
*want* to hide the source/target AoR and anti-replay info, but for other 
reasons generally.  So I'm proposing creating specific headers to contain the 
same type of info.

-hadriel
_______________________________________________
Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [EMAIL PROTECTED] for questions on current sip
Use [EMAIL PROTECTED] for new developments on the application of sip

Reply via email to