Steinmann, Martin (BL60:2500) wrote:
> An external request would be sent to the domain, e.g. [EMAIL PROTECTED]
> The internal mapping after passing through the SBC would route this to
> the sipXecs server, correct?  In that sense individual phones are not
> accessible from the outside and therefore all requests would pass
> through the proposed auth plugin and get denied.
> 

AFAIK, for the most part, as long as the system is behind a SBC, or a firewall, 
I don't think it will present a problem. However, it will be an issue for 
systems with phones that are on publicly route-able networks (where, you can 
just ring the phone to get its contact info, and then send a SUBSCRIBE straight 
to that address - effectively bypassing the proxy + auth plugin).


> Is there a use case where the external requester would have or could be
> given a set of credentials so that authentication can occur
> successfully?

Not that i know of. It might be possible to manually add credentials of 
external users to the credentialDB and use it, but I haven't tested it out yet.


> 
> Would it make sense to make this configurable so that the admin at least
> could disable authentication?
> 

Yes, it would make sense in cases where the system's installed in a private, 
secure network. I guess it wouldn't be of much a concern if anyone within that 
network can subscribe to dialog-events. I will add this as well.


Arjun

_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to