On Tue, 2008-11-18 at 13:03 -0500, Paul Mossman wrote:
> 
> Martin wrote:
> > To make sure I understand this correctly: For every external 
> > domain that is allowed to monitor phones on my system, I 
> > would have to add that domain with one common set of 
> > credentials to the table.

I think that for 4.0 the best thing to do is to require an identity in
the local domain to SUBSCRIBE to dialog events through the RLS.

This would mean that an external user without any local credentials
would not be able to monitor dialogs unless they were able to route the
SUBSCRIBE directly to the phone (which will depend on the topology of
the local network and the behavior of any SBC at its edge).  

Note that in the above "external" does not refer just to topologically
outside the local network - it means a phone that does not have
credentials for our domain.  A physically remote phone that has
connectivity to the local domain and has an address on the local system
with credentials is, for these purposes, not an external user.
Provisioning a remote phone like this is just like putting an external
line on one of our existing supported phones, so it won't need any
support we don't already have.

I very much doubt that anyone actually would _want_ random
unauthenticated people to be able to monitor dialogs on their PBX, so I
don't think that the fact that it can be done now and won't be possible
in 4.0 is going to bother anyone - I suspect that we can just say it's a
bug fix and everyone will agree.

So... I think the only fix needed for 4.0 is that we require normal SIP
authentication using our existing credentials database to create a
subscription at the RLS.
More elaborate federation schemes can wait.


_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to