On Fri, 2008-11-14 at 12:20 -0500, Martin Steinmann wrote: > >need to be handled by the RLS > > > >Hi, > > > >With regards to this issue, and I have quick question. If we delegate > all >dialog-event subscriptions to the RLS, then won't phones which > don't >support "eventlist" (but support application/dialog-info+xml) be > affected? > > This is for _external_ requests for subscriptions, meaning requests that > originate from a different domain than the one controlled by this > instance of sipXecs. Right now subscriptions get forwarded to the phone > and are handled peer-to-peer with no ability to allow/deny them on a > system level. XECS-1517 asks that all such _external_ subscription > requests for presence be funneled through the RLS. This helps not only > with security, but also with phones that do not handle multiple > subscriptions well.
Note that depending on the deployment environment, this may not protect the endpoints. An attacker can get the contact URI for a phone just by ringing it, and unless something outside sipXecs prevents it, the attacker can send a SUBSCRIBE directly to that phone, bypassing our proxy and any protections we impose. _______________________________________________ sipx-dev mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-dev Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
