On 8/1/08 11:05 AM, Dean Willis wrote:
Here's the problem... if I trust a B2BUA, it doesn't necessarily
mean that I'll trust everything it trusts. If Bob's UA is going to
make an informed choice, we need it to be able to examine a chain
of custody for the identity, at the very least.
Is the stack of "verified by" parameters in history-Info adequate,
or do you want to be able to check each transitive crypto operation?
If the latter, we'd have to do something like add each pre-edit
message as a sipfrag body onto the current message. That could make
for some rather large SIP requests. Maybe a diff format could make
it better, but it is still going to get chunky.
How many editing boxes do you expect in the middle here?