> >For xecs-1606, I am proposing to write an auth-plugin that will >authenticate any dialog-event SUBSCRIBEs addressed to our domain. This >means that we lock out all users from external domains (i.e. users we have >no credentials for), unless of course they send the SUBSCRIBE straight to >the phone, in which case there is nothing we can do.
An external request would be sent to the domain, e.g. [EMAIL PROTECTED] The internal mapping after passing through the SBC would route this to the sipXecs server, correct? In that sense individual phones are not accessible from the outside and therefore all requests would pass through the proposed auth plugin and get denied. Is there a use case where the external requester would have or could be given a set of credentials so that authentication can occur successfully? > >Regarding federated systems, I spoke with bob briefly about it, and he >mentioned one way to do this would be to establish a TLS connection to the >trusted domains. All dialog event requests coming from these connections >will not require local authentication. However, it is not really feasible >to do this right now, as we don't yet support TLS. So, for now, all >external users are locked out. Would it make sense to make this configurable so that the admin at least could disable authentication? --martin > >Arjun > _______________________________________________ sipx-dev mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-dev Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
