[OpenSER-Devel] nonce errors in trunk

Juha Heinanen jh at tutpro.com
Fri Jun 6 17:53:59 CEST 2008


Bogdan-Andrei Iancu writes:

 > I'm not saying that re-using the nonce is against RFC and that the phone 
 > is broken  - I'm saying it is a security issue (stolen credentials) and 
 > rejecting such auth requests does not break anything.

in that case i would say that ERROR level messages should be downgraded
to warning or notice, because there is no error.

-- juha



More information about the Devel mailing list