Showing posts with label ipsec. Show all posts
Showing posts with label ipsec. Show all posts

2010-01-26

New Release of Mercuro IMS Client (4.0.1594)


The latest release of Mercuro IMS Client (Version 4.0.1594) is available for download at http://www.mercuro.net/.

This release comes with fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Fix audio mixing when dealing with multiple streams

[SILVER, GOLD]
- Fix IPSec SPI storage for value greater than 2147483647
- Fix occasional TCP retransmission of SIP traffic

[GOLD]
- Fix UI glitches

Your feedback is welcomed (http://feedback.mercuro.net/)

2010-01-11

New Release of Mercuro IMS Client (4.0.1577)

The latest release of Mercuro IMS Client (Version 4.0.1577) is available for download at http://www.mercuro.net/.

This release comes with fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Add support for SIP dialog forking for VoIP sessions.
- Add new 3 UI Theme Palettes
- Add "Privacy" headers in 180/183 responses.
- Fix SUBSCRIBE/NOTIFY handling with "deactivated", "timeout" and "noresource" subscription state.
- Fix support for 64 bits platforms. No hack needed anymore to run Mercuro.
- Fix UI crashes when reconnecting with Microsoft Remote Desktop.
- Fix UI glitches with high-DPI fonts.

[SILVER, GOLD]
- Remove "rport" parameter from IPSec protected requests.

[GOLD]
- Fix SigComp support for TCP so NACK are sent on unacknowledged states.

- Fix parsing of DHCP Option 120 with IP Addresses


Your feedback is welcomed (http://feedback.mercuro.net/)

2009-11-06

Windows 7 support

We had a lot of queries regarding the support of Windows 7 for the Mercuro IMS Client. Well, the first tests we have made are pretty encouraging. As far as we know, there is no issue in running Mercuro on Windows 7. Yes, that means that even the IPSec works, as long as you run Mercuro as an administrator. If you encounter an issue under Windows 7, please let us know.

2009-07-15

New Release of Mercuro IMS Client (4.0.1448)

The latest release of Mercuro IMS Client(Version 4.0.1448) is now available for download at http://www.mercuro.net/.
This release comes with a lot of fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Add missing "c" attribute in OPTIONS/SDP
- Message-Summry subscription does not depend on the presence anymore
- Fix SDP media addition
- Fix MSRP overflow when dealing with very large file (> 2Gb)
- Fix H.263 payloading, to optimize blob splitting
- Fix a potential deadlock when dealing with subscriptions
- Fix MAC/XMAC mistmatch handling in AKAv1 and AKAv2
- Fix context menu for watcher info screen.
- Fix potential buffer overrun during AKA computation

[SILVER, GOLD]
- Add support for SigComp compression
- Add support for IPSec/AKA
- Fix potential SPI value overflow for IPSec/AKA
- Fix session timers triggering after a BYE
- Fix IPv6 handling when IPv6 addresses have a zone ID

[GOLD]
- Add for MMS/SMIL composition
- Add for MMS/SMIL rendering
- Fix Qos Pre-Conditions failure when session timers are used
- Fix mode-set negociation for AMR and AMR-WB

Your feedback is welcomed (http://feedback.mercuro.net/)
Mecuro DataSheet: http://www.mercuro.net/downloads/DataSheet_Mercuro.pdf

2009-04-07

New Release of Mercuro IMS Client (4.0.1258)

The latest release of Mercuro IMS Client(Version 4.0.1258) is now available for download at http://www.mercuro.net/.
This release comes with a some fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Fix crash when DNS request failed
- Fix crash when system time shifts during a session
- Add support for Early IMS authentication

[SILVER, GOLD]
- Fix Uri parsing when dealing with IPv6 domain
- Fix display of CPIM messages
- Add support for embedded images in MSRP
- Add support for QoS advertisement in 200OK OPTIONS

[GOLD]
- Fix protected source port for response with IPSec
- Fix re-registration temporary SA generation with IPSec

Your feedback is welcomed (http://feedback.mercuro.net/)

2009-03-19

New Release of Mercuro IMS Client (4.0.1236)

The latest release of Mercuro IMS Client(Version 4.0.1236) is now available for download at http://www.mercuro.net/.
This release comes with a some fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Add feedback message when call failed to establish.
- Add support for PRACK for Bronze edition.
- Use P-Asserted-Identity header to identify remote party if present.
- Fix DMTF keyboard so it does not overlap the video.
- Fix the crash when Web Browser is too slow to respond.
- Fix the crash when used for a long time with Remote Desktop or Terminal Services.

[SILVER, GOLD]
- Add ability to select the preferred identity.
- Finalize the support for session timers.
- Fix the download notification not to show up before activation.
- Fix activation failure with some license codes.
- Fix TLS certificates update in options.
- Fix update download error for Silver edition.

[GOLD]
- Add visual feedback when security agreement is used.
- IPSec client ports are now distincts.
- Finalize support for QoS PreConditions (as per RFC 3312).
- Fix DHCP discovery, so multiple domains are correctly handled.

Your feedback is welcomed (http://feedback.mercuro.net/)

2009-02-26

Inexbee joins the OpenIMSCore project

Inexbee is pleased to announce that one of the Mercuro's technical team member, Laurent Etiemble, has joined the OpenIMSCore project as a commiter. Most of the effort will be focused on the Gm and Ut interfaces (TLS, IPSec, etc.). Inexbee fully supports Open Source and is proud to allocate resources to such a successful project.

2009-02-09

New Release of Mercuro IMS Client (4.0.1178)

The latest release of Mercuro IMS Client(Version 4.0.1078) is now available for download at http://www.mercuro.net/.
This release comes with a some fixes and improvements. Here is a non-exhaustive list:

[BRONZE, SILVER, GOLD]
- Fix the update check to report if the check was successfull
- Fix a crash with MSRP chunk overflow
- Improve MSRP transfer speed

[SILVER, GOLD]
- Fix the DNS NAPTR when used on a mixed IP stack (IPv4/Ipv6)
- Fix configuration import/export
- Fix crash when Auto-Answer is enabled
- Fix emoticons egdes
- Enhance call transfer dialog
- Add support for CPIM (Common Presence and Instant Messaging)
- Add ability to set the Operator Identifier and AMF values

[GOLD]
- Add ESP (Null, AES, CBC) support for IPSec for IPv4 and IPv6 on Windows XP and Vista.

Your feedback is welcomed (http://feedback.mercuro.net/).

2008-10-07

Mercuro IMS Client and IPSec using Security Agreement (in 3GPP R5)

In this post I will try to explain how security mechanisms are negotiated between Mercuro IMS Client and the Proxy CSCF (only SIP headers) and how to setup SAs using Linux IPSec tools.

It’s important to keep in mind that the main purpose of Security agreement is to agree on which mechanisms, algorithms or security parameters to use.

Full version of Mercuro IMS Client support five mechanisms used in VoIP networks:

  1. Digest (fully tested)
  2. Tls (fully tested)
  3. ipsec-ike (under development)
  4. ipsec-man (under development)
  5. ipsec-3gpp (partially tested)

Mercuro IMS Client is specially focused on 3GPP IPSec because the IMS makes it mandatory. To enable IPSec feature you have to purchase a specific license. You can also get a private version with IPSec, TLS and Digest mechanisms if you are one of our technical partners.

When the Security Agreement feature is activated the mechanism to use is known after the negotiation between Mercuro IMS Client and the Proxy CSCF succeeds. This negotiation is performed during the IMS registration and authentication procedures.

Three new SIP header fields have been defined in Mercuro IMS Client, namely Security-Client, Security-Server and Security-Verify.

Call Flow

Mercuro IMS Client      Proxy CSCF        Serving CSCF
|                    |                  |
|----(1)REGISTER---->|                  |
|                    |                  |
|                    |---(2)REGISTER--->|
|                    |                  |
|                    |<-----(3) 401 ----|
|                    |                  |
|<----(4) 494/401----|                  |
|                    |                  |
|<==IPSec in place==>|                  |
|                    |                  |
|----(5)REGISTER---->|                  |
|                    |----(6)REGISTER-->|
|                    |                  |
|                    |<---(7) 200 OK----|
|<---(8) 200 OK------|                  |
|                    |                  |

In step (1) Mercuro IMS Client sends an unprotected registration request including the security-client header. Mercuro IMS Client indicates that it is able to negotiate security mechanism by adding “Require” and “Proxy-Require” headers. The security-client header includes two ports (client and server ports) that Mercuro IMS Client wants to negotiate with the proxy CSCF.

In step (2) the Proxy CSCF forwards the request to the Serving CSCF.

In step (3) the Serving CSCF (registrar) challenges the Proxy CSCF. The 401 response is sent to the Proxy CSCF (challenge parameters are under WWW-Authenticated header). The Serving CSCF must include the security-server header.

In step (4) the Proxy CSCF forwards the 401/494 response to Mercuro IMS Client. At this stage the Proxy CSCF opens the IPsec security association (SA) for Mercuro. Mercuro IMS Client also setup a SA (this is a temporary SA).

The lifetime of the created SA (between Mercuro IMS Client and the Proxy CSCF) is equal to the value of reg-await-auth timer (which guards the receipt of the next REGISTER request).

In step (5) Mercuro IMS Client sends a new registration (to the Proxy CSCF) request including its credentials and copies the content of security-server header to the security-verify header. Before forwarding the request to the Serving CSCF, the Proxy CSCF will check that the previous security-server header and the security-verify headers (added by Mercuro IMS Client) are identical. If these values are different, the Proxy CSCF sends an error message to Mercuro IMS Client and terminates the created SAs.

In step (6) the Proxy CSCF forwards the request to the Serving CSCF.

In step (7) the Serving CSCF authenticates Mercuro IMS Client, and responds with 200 OK.

In step (8) the Proxy CSCF forwards the response to Mercuro. At this step new SAs will be created. The temporary SAs will be destroyed (or not) by the Proxy CSCF.

Messages

(1)
REGISTER sip:pcscf.open-ims.test SIP/2.0
Security-Client: ipsec-3gpp; alg=hmac-md5-96; spi-c=1111; spi-s=2222; port-c=5062; port-s=5064
Require: sec-agree
Proxy-Require: sec-agree

(4)
SIP/2.0 [494 Security Agreement Required / 401 Unauthorized]
Security-Server: ipsec-3gpp; q=0.1; alg=hmac-md5-96; spi-c=3333; spi-s=4444; port-c=5066; port-s=5068

(5)
REGISTER sip:pcscf.open-ims.test SIP/2.0
Security-Client: ipsec-3gpp; alg=hmac-md5-96; spi-c=1111; spi-s=2222; port-c=5062; port-s=5064
Security-Verify: ipsec-3gpp; q=0.1; alg=hmac-md5-96; spi-c=3333; spi-s=4444; port-c=5066; port-s=5068
Require: sec-agree
Proxy-Require: sec-agree

Setting up SAs using Linux Tools

Here we suppose that:
- We are using Ubuntu (Linux Kernel 2.6 + KAME-tools)
- the Proxy-CSCF address is '192.168.0.10' and Mercuro IMS Client address is '192.168.0.11'
- for secure ports see above SIP capture
- protocol is esp
- algorithm is 'hmac-md5'
- encrypt-algorithm is 'des-ede3-cbc'
- mode is 'transport'
- confidentiality key is '123456789012123456789012' (see function f2345 in 3GPP milenage algorithms)
- integrity key is '1234567890123456' (see function f2345 in 3GPP milenage algorithms)

1. Install the tools

sudo apt-get install ipsec-tools

2. Edit /etc/ipsec-tools file and add the following script

#Incoming Requests [US <- PC]

spdadd 192.168.0.10/32[5066] 192.168.0.11/32[5064] udp -P in ipsec esp/transport//require;
add 192.168.0.10 192.168.0.11 esp 2222 -m transport -E des-ede3-cbc "123456789012123456789012" -A hmac-md5 "1234567890123456";

#Incoming Replies [UC <- PS]
spdadd 192.168.0.10/32[5068] 192.168.0.11/32[5062] udp -P in ipsec esp/transport//require;
add 192.168.0.10 192.168.0.11 esp 1111 -m transport -E des-ede3-cbc "123456789012123456789012" -A hmac-md5 "1234567890123456";

#Outgoing Requests [UC -> PS]
spdadd 192.168.0.11/32[5062] 192.168.0.10/32[5068] udp -P out ipsec esp/transport//unique:1;
add 192.168.0.11 192.168.0.10 esp 4444 -m transport -u 1 -E des-ede3-cbc "123456789012123456789012" -A hmac-md5 "1234567890123456";

#Outgoing Replies [US -> PC]
spdadd 192.168.0.11/32[5064] 192.168.0.10/32[5066] udp -P out ipsec esp/transport//unique:2;
add 192.168.0.11 192.168.0.10 esp 3333 -m transport -u 2 -E des-ede3-cbc "123456789012123456789012" -A hmac-md5 "1234567890123456";


3. Run the script

sudo /etc/init.d/setkey start

The same can be done under Windows vista using WFP(Windows Filtering Platform) API. For more information on How IPSec (in IMS context) feature could be implemented under Windows you can contact Mercuro Team at [tech dot mercuro -at- inexbee dot com].

For more information about Mercuro IMS Client visit http://www.mercuro.net

For more in formation about Secury Agreement see:

http://www.ietf.org/rfc/rfc3329.txt
http://www.arib.or.jp/IMT-2000/V310Sep02/T63/Rel5/33/A33203-520.pdf
http://www.arib.or.jp/IMT-2000/V310Sep02/S3g/Rel5/24/24229-510.pdf