Hi,

RFC 3261 section 26.3.2.4 provides additional recommendations concerning 401 
and 407.

"UAs and proxy servers SHOULD challenge questionable requests with
 only a single 401 (Unauthorized) or 407 (Proxy Authentication
 Required), forgoing the normal response retransmission algorithm, and
 thus behaving statelessly towards unauthenticated requests.

    Retransmitting the 401 (Unauthorized) or 407 (Proxy Authentication
    Required) status response amplifies the problem of an attacker
    using a falsified header field value (such as Via) to direct
    traffic to a third party."

> -----Original Message-----
> From: ankur bansal [mailto:[email protected]]
> Sent: Monday, December 30, 2013 3:25 AM
> To: Aditya Kumar
> Cc: [email protected]
> Subject: Re: [Sip-implementors] ACK timeout
> 
> Hi Aditya
> 
> Please go through Section 17.2.1 INVITE Server Transaction of RFC 3261
> 
> In brief , UE(trxn layer) should retransmit final response till Timer
> H(64
> * T1) fires .and if still ACK not came ,transaction will move to
> terminated
> state .
> 
> Thanks & regards
> Ankur Bansal
> 
> 
> On Sun, Dec 29, 2013 at 9:49 PM, Aditya Kumar
> <[email protected]>wrote:
> 
> > Hi,
> > UE Receives INVITE.
> > sends 486 //Any Failure 3xx,4xx,5xx,6xx
> > ACK is lost.
> >
> > what should be the behavior.
> > I mean for how much time should the UE keep the transaction state?
> > or wil do that clean up immediately?


_______________________________________________
Sip-implementors mailing list
[email protected]
https://lists.cs.columbia.edu/cucslists/listinfo/sip-implementors

Reply via email to