[SIPForum-discussion] 401 challenge with the stale =false

Rudra Kant Kanth rudra.k1 at gmail.com
Wed Dec 21 07:46:23 UTC 2011


Hi Juan,

The entry called "*stale: false*" is normal. What that entire line in the
response from the Server means that the user who sent the INVITE is not
authenticated and it needs to be MD5SUM authenticated. To do so
successfully, the server in it's 401 response also sends *WWW-Authenticate*
 header* *which contains entries as *realm*, *domain* and *nonce. *Upon
receipt of this response, the UA needs to pull the WWW-Authenticate header
and send out a a new INVITE with C_Seq increased and carrying an additional
header called *AUTHORIZATION *and providing the response of the needed
MD5SUM authentication.

This authorization-reject you would be seeing for almost all the new
requests which the UA would be generating. So, for all new requests you
would find something as:-
Request --------->
<---------------  401 Unauthorized (with WWW. Authenticate header)
Request --------->                     (with Authorization header)
<---------------  200 OK or any other appropriate Final Response

I am also attaching a sample trace for you to reference upon. In the
attached trace, you may want to ignore the parameter "P-Av Transport" as it
came because of the kind of the server I was using to register my UA.

I hope this helps.

Regards,
Rudra

On Sun, Dec 18, 2011 at 10:22 PM, Juan Garcia <juan.garcia at cableonda.net>wrote:

>
> Dear All,
>
> I have a situation were a sip gateway is loosing registration, but
> when it tries to re register the server sends a 401 requesting for the
> authorization credentials, my gateway doesnt send the re registration
> but after maybe 3 to 4 min and it is going without the credentials.
>
> But the stale parameter is = false. I want to know what does it really
> means stale = false, it is my understanding that this means that the
> UAS doesnt want the UAC to try to register anymore.
>
> Appreciate if someone can help
>
> This is the 401 challenge from the UAS can someone tell me if
> everything looks normal and that i should be able to re register
> sending the credentials here
>
>
> <--SIP/2.0 401 Unauthorized
> From:
> <sip:xxxx at xxxx:5060>;tag=1091fd0-ab59ec5-13c4-45028-66-1219efeb-66
> To: <sip:xxxx at xxxx:5060>;tag=4d03e817
> Call-ID: 10ac058-ab59ec5-13c4-45028-66-63fbd075-66
> CSeq: 1352 REGISTER
> Via: SIP/2.0/UDP
> 10.181.158.197:5060;branch=z9hG4bK-62935-1810f78c-21a4b0ad
> WWW-Authenticate: Digest
>
> realm="Huawei",domain="sip:Huawei.com",nonce="e7c0b2df970515626acca385e0f598da",stale=false,algorithm=MD5
> Server: Huawei SoftX3000 V300R601
> Content-Length: 0
>
> Thanks for the support
>
> JC
> _______________________________________________
> This is the SIP Forum discussion mailing list
> TO UNSUBSCRIBE, or edit your delivery options, please visit
> http://sipforum.org/mailman/listinfo/discussion
> Post to the list at discussion at sipforum.org
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://sipforum.org/pipermail/discussion/attachments/20111221/a6c1cb0f/attachment-0002.html>
-------------- next part --------------
REGISTER sip:abcde.com SIP/2.0
Route: <sip:1xx.1yy.1zz.216:15061;transport=TLS;lr>
From: sip:7001 at abcde.com;tag=-49f878874ee6e8b753724d70_F70011xx.1yy.1zz.30
To: sip:7001 at abcde.com
Call-ID: 1_48b635452d73e253724c30_R at 1xx.1yy.1zz.30
CSeq: 1 REGISTER
Via: SIP/2.0/TLS 1xx.1yy.1zz.244;branch=z9hG4bK1_48b6354-3899246853724c32_R7001-AP;ft=1215
Via: SIP/2.0/TLS 1xx.1yy.1zz.30:5061;branch=z9hG4bK1_48b6354-3899246853724c32_R7001
Content-Length: 0
P-Av-Transport: AP;fe=1xx.1yy.1zz.30:3282;ne=1xx.1yy.1zz.244:5061;tt=TLS
Max-Forwards: 69
Contact: <sip:7001 at 1xx.1yy.1zz.30:5061;transport=tls>;q=1.0;expires=3600;reg-id=1;+sip.instance="<urn:uuid:00000000-0000-1000-8000-00ff989cbb89>"
Allow: INVITE,CANCEL,BYE,ACK,SUBSCRIBE,NOTIFY,MESSAGE,INFO,PUBLISH,REFER,UPDATE
User-Agent: abcde IM Messanger
Supported: eventlist





SIP/2.0 401 Unauthorized
Via: SIP/2.0/TLS 1xx.1yy.1zz.244;branch=z9hG4bK1_48b6354-3899246853724c32_R7001-AP;ft=1215
Via: SIP/2.0/TLS 1xx.1yy.1zz.30:5061;branch=z9hG4bK1_48b6354-3899246853724c32_R7001
To: sip:7001 at abcde.com;tag=-1037157914*1*016abcde-callprocessing.sar-678522220~1323755703866~38636393~1
From: sip:7001 at abcde.com;tag=-49f878874ee6e8b753724d70_F70011xx.1yy.1zz.30
Call-ID: 1_48b635452d73e253724c30_R at 1xx.1yy.1zz.30
CSeq: 1 REGISTER
WWW-Authenticate: Digest realm="abcde.com", qop="auth", opaque="1234567890abcedef", nonce="13435fd0e3c7f1b90b5f182be093a1aa3052d0aef0b", algorithm=MD5, stale=false
Server:  Abcde-sip-server-6.1.5.0.615006
Content-Length: 0








REGISTER sip:abcde.com SIP/2.0
Route: <sip:1xx.1yy.1zz.216:15061;transport=TLS;lr>
From: sip:7001 at abcde.com;tag=-49f878874ee6e8b753724d70_F70011xx.1yy.1zz.30
To: sip:7001 at abcde.com
Call-ID: 1_48b635452d73e253724c30_R at 1xx.1yy.1zz.30
CSeq: 2 REGISTER
Via: SIP/2.0/TLS 1xx.1yy.1zz.244;branch=z9hG4bK2_48b6364-6e68c41f53724f42_R7001-AP;ft=1215
Via: SIP/2.0/TLS 1xx.1yy.1zz.30:5061;branch=z9hG4bK2_48b6364-6e68c41f53724f42_R7001
Content-Length: 0
P-Av-Transport: AP;fe=1xx.1yy.1zz.30:3282;ne=1xx.1yy.1zz.244:5061;tt=TLS
Max-Forwards: 69
Contact: <sip:7001 at 1xx.1yy.1zz.30:5061;transport=tls>;q=1.0;expires=3600;reg-id=1;+sip.instance="<urn:uuid:00000000-0000-1000-8000-00ff989cbb89>"
Allow: INVITE,CANCEL,BYE,ACK,SUBSCRIBE,NOTIFY,MESSAGE,INFO,PUBLISH,REFER,UPDATE
User-Agent: abcde IM Messanger
Supported: eventlist
Authorization: Digest username="7001",realm="abcde.com",nonce="13435fd0e3c7f1b90b5f182be093a1aa3052d0aef0b",uri="sip:abcde.com",response="3ccc829ca3ec2346907d8aeaf473998d",cnonce="0a4f113b",opaque="1234567890abcedef",qop=auth,nc=00000001





SIP/2.0 200 OK
Contact: <sip:7001 at abcde IM Messanger:5061;transport=tls>;expires=2901;q=1.0;reg-id=1;+sip.instance="<urn:uuid:00000000-0000-1000-8000-00ff989cbb89>"
Via: SIP/2.0/TLS 1xx.1yy.1zz.244:5061;branch=z9hG4bK2_48b6364-6e68c41f53724f42_R7001-AP;ft=1215
Via: SIP/2.0/TLS 1xx.1yy.1zz.30:5061;branch=z9hG4bK2_48b6364-6e68c41f53724f42_R7001
To: sip:7001 at abcde.com;tag=-1037157914*1*016abcde-callprocessing.sar-678522220~1323755703875~38636395~1
From: sip:7001 at abcde.com;tag=-49f878874ee6e8b753724d70_F70011xx.1yy.1zz.30:5061
Call-ID: 1_48b635452d73e253724c30_R at 1xx.1yy.1zz.30:5061
CSeq: 2 REGISTER
Date: Tue, 13 Dec 2011 05:55:03 GMT
Server:  Abcde-Sip-server-6.1.5.0.615006
Content-Length: 0



More information about the discussion mailing list