>
>For xecs-1606, I am proposing to write an auth-plugin that will
>authenticate any dialog-event SUBSCRIBEs addressed to our domain. This
>means that we lock out all users from external domains (i.e. users we
have >no credentials for), unless of course they send the SUBSCRIBE
straight to >the phone, in which case there is nothing we can do.

An external request would be sent to the domain, e.g. [EMAIL PROTECTED]
The internal mapping after passing through the SBC would route this to
the sipXecs server, correct?  In that sense individual phones are not
accessible from the outside and therefore all requests would pass
through the proposed auth plugin and get denied.

Is there a use case where the external requester would have or could be
given a set of credentials so that authentication can occur
successfully?

>
>Regarding federated systems, I spoke with bob briefly about it, and he
>mentioned one way to do this would be to establish a TLS connection to
the >trusted domains. All dialog event requests coming from these
connections >will not require local authentication. However, it is not
really feasible >to do this right now, as we don't yet support TLS. So,
for now, all >external users are locked out.

Would it make sense to make this configurable so that the admin at least
could disable authentication?

--martin

>
>Arjun
>

_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to