Hi Kennard
Kennard White wrote:
[....]
> Opensips has two mechanisms for making a nonce stale: the time-based
> mechanism (nonce_expire) and a use-once mechanism
> ('disable_nonce_check"). The 2nd mechanism doesn't set the stale=1
> flag. Not sure why, but I think maybe because authors assume that if
> this happened it was a malicious attack, not a retransmission.
[....]
actually that was a bug - the STALE indicator was report to the script,
but not included in the challenge ....It is fixed now.
Thanks and regards,
Bodgan
--
Bogdan-Andrei Iancu
OpenSIPS Bootcamp
15 - 19 November 2010, Edison, New Jersey, USA
www.voice-system.ro
_______________________________________________
Users mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/users