[OpenSIPS-Users] Which SIP messages to challange for authentication?

opensipslist at encambio.com opensipslist at encambio.com
Wed Jan 20 14:19:16 CET 2010


Hello list,

I know that strategies differ according to security needs but...

  Which SIP messages are typically challenged for authentication?

Right now we're challenging INVITE, SUBSCRIBE, and NOTIFY, although
it's not clear to me if challenging SUBSCRIBE or NOTIFY is useful.

Of course ACK and BYE are not challenged, but then there are others
like MESSAGE, INFO, OPTION... whatever. This falls in the gray zone
as far as my understanding of SIP and security go.

Regards,
Brian



More information about the Users mailing list