> > >On Tue, 2008-11-18 at 13:03 -0500, Paul Mossman wrote: >> >> Martin wrote: >> > To make sure I understand this correctly: For every external >> > domain that is allowed to monitor phones on my system, I >> > would have to add that domain with one common set of >> > credentials to the table. > >I think that for 4.0 the best thing to do is to require an identity in >the local domain to SUBSCRIBE to dialog events through the RLS. > >This would mean that an external user without any local credentials >would not be able to monitor dialogs unless they were able to route the >SUBSCRIBE directly to the phone (which will depend on the topology of >the local network and the behavior of any SBC at its edge). > >Note that in the above "external" does not refer just to topologically >outside the local network - it means a phone that does not have >credentials for our domain. A physically remote phone that has >connectivity to the local domain and has an address on the local system >with credentials is, for these purposes, not an external user. >Provisioning a remote phone like this is just like putting an external >line on one of our existing supported phones, so it won't need any >support we don't already have.
Typically when an external user wants to subscribe to presence of a phone on my sipXecs you would not use an external line, but simply define a speed dial entry to that contact on the external phone. The speed dial entry page does not allow adding credentials, so how would this work? > >I very much doubt that anyone actually would _want_ random >unauthenticated people to be able to monitor dialogs on their PBX, so I >don't think that the fact that it can be done now and won't be possible >in 4.0 is going to bother anyone - I suspect that we can just say it's a >bug fix and everyone will agree. We are speculating again about what users _want_ or _don't want_. In the absence of a closer analysis I would like to maintain my requirement of making this configurable so that authentication can be turned off on 4.0, which would render the same system behavior we have to day with 3.10. --martin > >So... I think the only fix needed for 4.0 is that we require normal SIP >authentication using our existing credentials database to create a >subscription at the RLS. >More elaborate federation schemes can wait. > _______________________________________________ sipx-dev mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-dev Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
