On 7/22/14 6:38 AM, Sunil P wrote:
Hi Paul,

       Wrong P-Asserted Identity means  the one which was not in the
list of P-Associated URI.I am not sure
whether to send 403 since i couldn't get the reference of exact behavior
in the RFC.

This is really an IMS question, so I'm not an ideal person to answer.

You have presented this as a question from the perspective of the P-CSCF. But you didn't say *which* P-CSCF - that of the originator, or of the target of the request? Or are they the same in this case?

ISTM that this is first and foremost an error on the part of the originating P-CSCF. It should not have let this pass. IIUC, the proper sequence is that the originating UE inserts a *P-Preferred-Identity* header, not P-Asserted-Identity. I think the P-CSCF should filter out any P-Asserted-Identity headers, unless it can verify that they are correct, because once the request is within the trust domain those P-Asserted-Identity headers will be trusted. It could either just remove those bogus headers or reject the request.

If somehow that doesn't happen, then the originating P-CSCF should probably validate the validity of any received P-Asserted-Identity headers and either remove them or reject the request. This is all before any consideration of what sort of request this is or what the destination is.

After that, when the request reaches the terminating P-CSCF (even if that is the same as the originating P-CSCF) the P-Asserted-Identity headers may be trusted. At this point it becomes an authorization decision - is this requesting identity *authorized* to make this request. That is a different sort of decision.

        Thanks,
        Paul

Thanks and Regards,
Sunil



    Message: 2
    Date: Sun, 20 Jul 2014 14:35:30 -0400
    From: Paul Kyzivat <[email protected]
    <mailto:[email protected]>>
    To: [email protected]
    <mailto:[email protected]>
    Subject: Re: [Sip-implementors] Wrong P-Asserted Identity in Subscribe
             Message to CSCF
    Message-ID: <[email protected]
    <mailto:[email protected]>>
    Content-Type: text/plain; charset=ISO-8859-1; format=flowed

    Sunil,

    What do you mean by "wrong"?

    This is used with transitive trust, so presumably you should trust the
    sender to have asserted the correct identity of the sender.

    Do you mean that this identity is not authorized to make the
    subscription it is requesting? If so, then I guess the proper response
    is 403 Forbidden.

             Thanks,
             Paul

    On 7/20/14 2:07 PM, Sunil P wrote:
     > Hi All,
     >
     >          What should be the behavior of  CSCF if it receives
    Subscribe
     > request from UE
     > with wrong P-Asserted Identity header?.
     >
     > Thanks and Regards,
     > Sunil
     > _______________________________________________
     > Sip-implementors mailing list
     > [email protected]
    <mailto:[email protected]>
     > https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors
     >



    ------------------------------

    Message: 3
    Date: Mon, 21 Jul 2014 09:17:44 +0800
    From: "=?gb18030?B?U2FtbWFu?=" <[email protected]
    <mailto:[email protected]>>
    To: "=?gb18030?B?TmVlbGFrYW50YW4sIE5lZWw=?="
             <[email protected]
    <mailto:[email protected]>>, "=?gb18030?B?UHJha2FzaCBL?="
             <[email protected] <mailto:[email protected]>>,

    "=?gb18030?B?c2lwLWltcGxlbWVudG9yc0BsaXN0cy5jcy5jb2x1bWJpYS5lZHU=?="
             <[email protected]
    <mailto:[email protected]>>
    Subject: Re: [Sip-implementors] Message Body in ACK other than SDP
    Message-ID: <[email protected]
    <mailto:[email protected]>>
    Content-Type: text/plain;       charset="gb18030"

    please Refer to RFC3264




    ------------------ Original ------------------
    From: "Neelakantan, Neel"<[email protected]
    <mailto:[email protected]>>;
    Date: 2014?7?18?(???) ??11:19
    To: "Prakash K"<[email protected]
    <mailto:[email protected]>>;
    "[email protected]
    
<mailto:[email protected]>"<[email protected]
    <mailto:[email protected]>>;
    Subject: Re: [Sip-implementors] Message Body in ACK other than SDP



    The ACK can have a message body, if the Offer/Answer is done in 200
    OK/ACK.  The offer/answer can have multipart-mime message body.  In
    that case, ACK can have multipart-mime body (with embedded SDP).

    Thanks,
    Neel.


     > -----Original Message-----
    &gt; From: [email protected]
    <mailto:[email protected]> [mailto:sip-
    <mailto:sip->
    &gt; [email protected]
    <mailto:[email protected]>] On Behalf Of
    Prakash K
     > Sent: Wednesday, July 16, 2014 11:58 AM
    &gt; To: [email protected]
    <mailto:[email protected]>
     > Subject: [Sip-implementors] Message Body in ACK other than SDP
     >
     > Hi All,
     >
     > Is there any usecase or standards/RFC define that ACK method can
    carry
     > Message body otherthan SDP
     >
     > --
     > Thanks
     > Prakash K
     > _______________________________________________
     > Sip-implementors mailing list
    &gt; [email protected]
    <mailto:[email protected]>
    &gt; https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors
    _______________________________________________
    Sip-implementors mailing list
    [email protected]
    <mailto:[email protected]>
    https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors

    ------------------------------

    Message: 4
    Date: Mon, 21 Jul 2014 10:56:32 +0530
    From: Raghavendra D P <[email protected]>
    To: Sunil P <[email protected] <mailto:[email protected]>>,
             "[email protected]
    <mailto:[email protected]>"
             <[email protected]
    <mailto:[email protected]>>
    Subject: Re: [Sip-implementors] Wrong P-Asserted Identity in Subscribe
             Message to CSCF
    Message-ID:

    <84dd18eec80aa5439fcf0741b858002d912bcf6...@sinchnmbx001.techmahindra.com
    
<mailto:84dd18eec80aa5439fcf0741b858002d912bcf6...@sinchnmbx001.techmahindra.com>>

    Content-Type: text/plain; charset="us-ascii"

    Hi  Sunil,
    P-Asserted identity is added by  P-CSCF   not the UE.
    UE adds  P-Preferred Identity  in SIP Request , P-CSCF using this
    information P-CSCF adds P-Asserted Identity header.

    Regards
    Raghavendra DP


    -----Original Message-----
    From: [email protected]
    <mailto:[email protected]>
    [mailto:[email protected]
    <mailto:[email protected]>] On Behalf
    Of Sunil P
    Sent: Sunday, July 20, 2014 11:37 PM
    To: [email protected]
    <mailto:[email protected]>
    Subject: [Sip-implementors] Wrong P-Asserted Identity in Subscribe
    Message to CSCF

    Hi All,

             What should be the behavior of  CSCF if it receives
    Subscribe request from UE with wrong P-Asserted Identity header?.

    Thanks and Regards,
    Sunil
    _______________________________________________
    Sip-implementors mailing list
    [email protected]
    <mailto:[email protected]>
    https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors


    
============================================================================================================================
    Disclaimer:  This message and the information contained herein is
    proprietary and confidential and subject to the Tech Mahindra policy
    statement, you may review the policy at
    http://www.techmahindra.com/Disclaimer.html externally
    http://tim.techmahindra.com/tim/disclaimer.html internally within
    TechMahindra.
    
============================================================================================================================



    ------------------------------

    Message: 5
    Date: Mon, 21 Jul 2014 12:41:26 +0530
    From: Sunil P <[email protected] <mailto:[email protected]>>
    To: Raghavendra D P <[email protected]
    <mailto:[email protected]>>
    Cc: "[email protected]
    <mailto:[email protected]>"
             <[email protected]
    <mailto:[email protected]>>
    Subject: Re: [Sip-implementors] Wrong P-Asserted Identity in Subscribe
             Message to CSCF
    Message-ID:

    <cahfffazofizx0q5eicqtf81dlzazicaskxavhgmaerq684g...@mail.gmail.com
    <mailto:cahfffazofizx0q5eicqtf81dlzazicaskxavhgmaerq684g...@mail.gmail.com>>
    Content-Type: text/plain; charset=UTF-8

    Hi Raghavendra,

      UAC can add P-ASSERTED Identity.Please refer RFC 5876.

    Thanks and Regards,
    Sunil


    On Mon, Jul 21, 2014 at 10:56 AM, Raghavendra D P <
    [email protected] <mailto:[email protected]>> wrote:

     > Hi  Sunil,
     > P-Asserted identity is added by  P-CSCF   not the UE.
     > UE adds  P-Preferred Identity  in SIP Request , P-CSCF using this
     > information P-CSCF adds P-Asserted Identity header.
     >
     > Regards
     > Raghavendra DP
     >
     >
     > -----Original Message-----
     > From: [email protected]
    <mailto:[email protected]> [mailto:
     > [email protected]
    <mailto:[email protected]>] On Behalf
    Of Sunil P
     > Sent: Sunday, July 20, 2014 11:37 PM
     > To: [email protected]
    <mailto:[email protected]>
     > Subject: [Sip-implementors] Wrong P-Asserted Identity in
    Subscribe Message
     > to CSCF
     >
     > Hi All,
     >
     >         What should be the behavior of  CSCF if it receives Subscribe
     > request from UE with wrong P-Asserted Identity header?.
     >
     > Thanks and Regards,
     > Sunil
     > _______________________________________________
     > Sip-implementors mailing list
     > [email protected]
    <mailto:[email protected]>
     > https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors
     >
     >
     >
     >
    
============================================================================================================================
     >
     > Disclaimer:  This message and the information contained herein is
     > proprietary and confidential and subject to the Tech Mahindra policy
     > statement, you may review the policy at
     > http://www.techmahindra.com/Disclaimer.html externally
     > http://tim.techmahindra.com/tim/disclaimer.html internally within
     > TechMahindra.
     >
     >
     >
    
============================================================================================================================
     >
     >
     >


    ------------------------------

    Message: 6
    Date: Mon, 21 Jul 2014 13:18:21 +0530
    From: Pranav Damele <[email protected]
    <mailto:[email protected]>>
    To: Sunil P <[email protected] <mailto:[email protected]>>
    Cc: "[email protected]
    <mailto:[email protected]>"
             <[email protected]
    <mailto:[email protected]>>
    Subject: Re: [Sip-implementors] Wrong P-Asserted Identity in Subscribe
             Message to CSCF
    Message-ID:

    <camae1vjt6emwxsxlctv6cm8njs-kmndmyhz9g91ghrkgn7-...@mail.gmail.com
    <mailto:camae1vjt6emwxsxlctv6cm8njs-kmndmyhz9g91ghrkgn7-...@mail.gmail.com>>
    Content-Type: text/plain; charset=UTF-8

    Hey Sunil,

    It will remove the incoming PAID header and then will insert PAID header
    based on AOR match.
    I think it will do regardless the incoming PAID is correct or not
    (according to PUI in 200 OK received at the time of UE's Registration).

    Regards,
    Pranav Damele

    Associate Consultant - Engineering, Product Engineering and Development
    *Mobile:* +91-9818-92-4466
    *Email:* [email protected] <mailto:[email protected]>
    *IM:* pranavdamele (Skype)
      *http://in.linkedin.com/in/pranavdamele
    <http://in.linkedin.com/in/pranavdamele>*


    On 20 July 2014 23:37, Sunil P <[email protected]
    <mailto:[email protected]>> wrote:

     > Hi All,
     >
     >         What should be the behavior of  CSCF if it receives Subscribe
     > request from UE
     > with wrong P-Asserted Identity header?.
     >
     > Thanks and Regards,
     > Sunil
     > _______________________________________________
     > Sip-implementors mailing list
     > [email protected]
    <mailto:[email protected]>
     > https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors
     >


    ------------------------------

    _______________________________________________
    Sip-implementors mailing list
    [email protected]
    <mailto:[email protected]>
    https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors


    End of Sip-implementors Digest, Vol 5, Issue 20
    ***********************************************



_______________________________________________
Sip-implementors mailing list
[email protected]
https://lists.cs.columbia.edu/mailman/listinfo/sip-implementors

Reply via email to