[asterisk-bugs] [JIRA] (ASTERISK-25835) Authentication using 'Username' field from Digest

Ross Beer (JIRA) noreply at issues.asterisk.org
Mon Mar 7 13:46:56 CST 2016


Ross Beer created ASTERISK-25835:
------------------------------------

             Summary: Authentication using 'Username' field from Digest
                 Key: ASTERISK-25835
                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-25835
             Project: Asterisk
          Issue Type: Improvement
      Security Level: None
          Components: Channels/chan_pjsip
    Affects Versions: 13.7.2
         Environment: Centos 7
            Reporter: Ross Beer


At present 'res_pjsip_endpoint_identifier_user' only uses the 'From' header to match username, however commonly the from field contains the Caller ID instead of a username.

The response to an unauthorised challenge contains a username field and, therefore, should be used to match and endpoint.



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list