mirror of
https://github.com/asterisk/asterisk.git
synced 2026-07-27 16:07:15 -07:00
Disables auth_options_request option by default.
The auth_options_request option was created to do authentication on OPTIONS request just like INVITES are done. Since it has been noted that some endpoints use OPTIONS requests as a way of qualifying a peer and that a 401 authentication response could result in interoperability issues, this option has been disabled by default. git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.8@285006 65c4cc65-6c06-0410-ace0-fbb531ad65f3
This commit is contained in:
+3
-3
@@ -26371,7 +26371,7 @@ static int reload_config(enum channelreloadreason reason)
|
||||
sip_cfg.notifyhold = FALSE; /*!< Keep track of hold status for a peer */
|
||||
sip_cfg.directrtpsetup = FALSE; /* Experimental feature, disabled by default */
|
||||
sip_cfg.alwaysauthreject = DEFAULT_ALWAYSAUTHREJECT;
|
||||
sip_cfg.auth_options_requests = 1;
|
||||
sip_cfg.auth_options_requests = DEFAULT_AUTH_OPTIONS;
|
||||
sip_cfg.allowsubscribe = FALSE;
|
||||
sip_cfg.disallowed_methods = SIP_UNKNOWN;
|
||||
sip_cfg.contact_ha = NULL; /* Reset the contact ACL */
|
||||
@@ -26613,8 +26613,8 @@ static int reload_config(enum channelreloadreason reason)
|
||||
} else if (!strcasecmp(v->name, "alwaysauthreject")) {
|
||||
sip_cfg.alwaysauthreject = ast_true(v->value);
|
||||
} else if (!strcasecmp(v->name, "auth_options_requests")) {
|
||||
if (ast_false(v->value)) {
|
||||
sip_cfg.auth_options_requests = 0;
|
||||
if (ast_true(v->value)) {
|
||||
sip_cfg.auth_options_requests = 1;
|
||||
}
|
||||
} else if (!strcasecmp(v->name, "mohinterpret")) {
|
||||
ast_copy_string(default_mohinterpret, v->value, sizeof(default_mohinterpret));
|
||||
|
||||
@@ -207,6 +207,7 @@
|
||||
#define DEFAULT_QUALIFY FALSE /*!< Don't monitor devices */
|
||||
#define DEFAULT_CALLEVENTS FALSE /*!< Extra manager SIP call events */
|
||||
#define DEFAULT_ALWAYSAUTHREJECT TRUE /*!< Don't reject authentication requests always */
|
||||
#define DEFAULT_AUTH_OPTIONS FALSE
|
||||
#define DEFAULT_REGEXTENONQUALIFY FALSE
|
||||
#define DEFAULT_T1MIN 100 /*!< 100 MS for minimal roundtrip time */
|
||||
#define DEFAULT_MAX_CALL_BITRATE (384) /*!< Max bitrate for video */
|
||||
|
||||
@@ -370,13 +370,8 @@ srvlookup=yes ; Enable DNS SRV lookups on outbound calls
|
||||
; the ability of an attacker to scan for valid SIP usernames.
|
||||
; This option is set to "yes" by default.
|
||||
|
||||
;auth_options_requests = no ; sip OPTIONS requests should be treated the exact same as
|
||||
; an INVITE, this includes performing authentication. By default
|
||||
; OPTIONS requests are authenticated, however this option allows
|
||||
; OPTION requests to proceed unauthenticated in order to increase
|
||||
; performance. This may be desirable if OPTIONS are only used to
|
||||
; qualify the availabilty of the endpoint/extension. Disabling
|
||||
; this option is not recommended.
|
||||
;auth_options_requests = yes ; Enabling this option will authenticate OPTIONS requests just like
|
||||
; INVITE requests are. By default this option is disabled.
|
||||
|
||||
;g726nonstandard = yes ; If the peer negotiates G726-32 audio, use AAL2 packing
|
||||
; order instead of RFC3551 packing order (this is required
|
||||
|
||||
Reference in New Issue
Block a user