Hadriel, Should we specify something that would make life easier for proxies/B2BUAs to detect compliance with this, e.g., a magic string at the start of the call-ID, rather than simply the absence of "@"?
John > -----Original Message----- > From: sip-boun...@ietf.org [mailto:sip-boun...@ietf.org] On > Behalf Of Hadriel Kaplan > Sent: 05 March 2009 00:29 > To: SIP > Subject: [Sip] I-D Inaction: draft-kaplan-sip-secure-call-id-00.txt > > Howdy, > In an effort to avoid endless thrashing, I will be updating > the Session-ID draft to only be about troubleshooting use. > For dialog matching issues, I have followed Adam's advice and > submitted a separate draft to update RFC 3261, linked below. > This issue will only get worse, and the code changes to do > this should be fairly small for most folks, I would think. > And it's only 6 pages, so we should be able to agree on this > in about 3 years. :) > > A New Internet-Draft is available from the on-line > Internet-Drafts directories. > > Title : A Secure Call-ID for the Session > Initiation Protocol (SIP) > Author(s) : H. Kaplan > Filename : draft-kaplan-sip-secure-call-id-00.txt > Pages : 6 > Date : 2009-03-04 > > Many SIP devices generate Call-ID values which contain their > system IP Address, due to examples and normative text in RFC > 3261. This has led to some middleboxes, such as SBC's, to > change the Call-ID for security reasons. This draft updates > RFC 3261 to require SIP User Agents to generate benign > Call-IDs, in such a manner that they can be detected as > secure and not need to be changed. > > A URL for this Internet-Draft is: > http://www.ietf.org/internet-drafts/draft-kaplan-sip-secure-ca > ll-id-00.txt > > > -hadriel > _______________________________________________ > Sip mailing list https://www.ietf.org/mailman/listinfo/sip > This list is for NEW development of the core SIP Protocol > Use sip-implement...@cs.columbia.edu for questions on current sip > Use sipp...@ietf.org for new developments on the application of sip > _______________________________________________ Sip mailing list https://www.ietf.org/mailman/listinfo/sip This list is for NEW development of the core SIP Protocol Use sip-implement...@cs.columbia.edu for questions on current sip Use sipp...@ietf.org for new developments on the application of sip