On Fri, 2019-03-01 at 15:41 -0500, Joshua C. Colp wrote: > > I don't understand what you mean. Your ITSP has stated that they > don't want you to do authentication with them, so you can't.
They are implying, as I am understanding them, that somehow SIP packets they send me shouldn't need to be authenticated because they are associated (i.e. "identify"ed in pjsip nomenclature) with my registration to them. It all sounds suspect to me but that's what I am understanding them to be saying. Ultimately, if I have this endpoint and it's unauthenticated, does it create a security risk? I suppose anyone could forge a UDP packet as coming from their IP address, and as it's "identify"ed by IP on my side and I would accept it without authentication being necessary. But then I suppose they are only getting access to being able to connect into an incoming dialplan context, so ringing extensions here, but not being able to launch in and outbound (money costing) phone call, at least without there being dialplan support to make outgoing calls when calling in (i.e. like a calling card application or somesuch, which should have it's own authentication anyway). > If you are referring to the template - it's a template so by itself > does not create an endpoint. Yes, completely understood. b.
signature.asc
Description: This is a digitally signed message part
-- _____________________________________________________________________ -- Bandwidth and Colocation Provided by http://www.api-digital.com -- Check out the new Asterisk community forum at: https://community.asterisk.org/ New to Asterisk? Start here: https://wiki.asterisk.org/wiki/display/AST/Getting+Started asterisk-users mailing list To UNSUBSCRIBE or update options visit: http://lists.digium.com/mailman/listinfo/asterisk-users