> -----Original Message----- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of > Michael Thomas > > > Therein lies the conundrum with intermediate manglers like B2BUA's > and mailing lists managers, etc. On the one hand, you can sign very little > and be far more successful at surviving the mangler. However, that's > buying > you very, very little since things that the manglers mangle are the very > things > that you want to protect. So why bother.
So the question is: what is it that you really want to protect? Is it literally the To/From/Call-id/etc. headers; or is it the source AoR, target AoR, and some additional info to prevent replay? My belief is the latter. Using the To/From/Call-id/etc. in 4474 was essentially a convenience, because the assumption was the info is already in those headers so one might as well reuse them for 4474's purpose. But for some deployment scenarios those headers get changed - not because the changers *want* to hide the source/target AoR and anti-replay info, but for other reasons generally. So I'm proposing creating specific headers to contain the same type of info. -hadriel _______________________________________________ Sip mailing list https://www.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use [EMAIL PROTECTED] for questions on current sip Use [EMAIL PROTECTED] for new developments on the application of sip
