On Fri, 2008-11-14 at 12:20 -0500, Martin Steinmann wrote:
> >need to be handled by the RLS
> >
> >Hi,
> >
> >With regards to this issue, and I have quick question. If we delegate
> all >dialog-event subscriptions to the RLS, then won't phones which
> don't >support "eventlist" (but support application/dialog-info+xml) be
> affected?
> 
> This is for _external_ requests for subscriptions, meaning requests that
> originate from a different domain than the one controlled by this
> instance of sipXecs. Right now subscriptions get forwarded to the phone
> and are handled peer-to-peer with no ability to allow/deny them on a
> system level. XECS-1517 asks that all such _external_ subscription
> requests for presence be funneled through the RLS. This helps not only
> with security, but also with phones that do not handle multiple
> subscriptions well. 

Note that depending on the deployment environment, this may not protect
the endpoints.  An attacker can get the contact URI for a phone just by
ringing it, and unless something outside sipXecs prevents it, the
attacker can send a SUBSCRIBE directly to that phone, bypassing our
proxy and any protections we impose.

_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to