sip-5----Page:9
1  2  3  4  5  6  7  8  9  10 

Adding Bodies Safely: Secure and Backwards Compatible
biloxi.com may only add a body to a request when retargeting to a UAS registered in the biloxi.com domain (for example: Bob). Never responses.
Any additions are always marked as “added-by” biloxi.com. Biloxi either signs its additions with S/MIME or forwards them directly over TLS to Bob
Bob includes an option-tag in a REGISTER to indicate it supports body repacking.
Q: Is this secure? See the Contact—AOR correlation problem…
PPT Version