[sr-dev] Stale nonce for Authentication

Juha Heinanen jh at tutpro.com
Fri May 27 21:41:07 CEST 2011


martin,

what was the conclusion regarding your stale nonce param patch?

i would do it so that if www or proxy_authorize function returns -4
(stale nonce) then i would call www or proxy_challenge with stale flag
on.  it would then cause stale=true to be added to the header.

i don't understand why your patch calls pre_auth, since the request was
already authenticated and it failed due to stale nonce.

-- juha



More information about the sr-dev mailing list