sip-4----Page:3
1  2  3  4  5  6  7  8  9  10 

What is Response Identity?
A mechanism that allows UACs to detect that responses come from an impersonator
Flip side of request identity
sip-identity-04 wouldn’t work if it were applied as-is to responses (assuming flipping From for To)
The problem: signature over the To header field in a response would come from the actual ‘connected’ domain
-Not- the original target domain of the request, when retargeting has taken place
Thus, the root cause of response identity problems is retargeting
That is, if there were no retargeting, response identity would “just work”

PPT Version