Steinmann, Martin (BL60:2500) wrote: > An external request would be sent to the domain, e.g. [EMAIL PROTECTED] > The internal mapping after passing through the SBC would route this to > the sipXecs server, correct? In that sense individual phones are not > accessible from the outside and therefore all requests would pass > through the proposed auth plugin and get denied. >
AFAIK, for the most part, as long as the system is behind a SBC, or a firewall, I don't think it will present a problem. However, it will be an issue for systems with phones that are on publicly route-able networks (where, you can just ring the phone to get its contact info, and then send a SUBSCRIBE straight to that address - effectively bypassing the proxy + auth plugin). > Is there a use case where the external requester would have or could be > given a set of credentials so that authentication can occur > successfully? Not that i know of. It might be possible to manually add credentials of external users to the credentialDB and use it, but I haven't tested it out yet. > > Would it make sense to make this configurable so that the admin at least > could disable authentication? > Yes, it would make sense in cases where the system's installed in a private, secure network. I guess it wouldn't be of much a concern if anyone within that network can subscribe to dialog-events. I will add this as well. Arjun _______________________________________________ sipx-dev mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-dev Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
