ietf-corpus

rfc-8898

Third-Party Token-Based Authentication and Authorization for Session Initiation Protocol (SIP)

R. Shekh-Yusef, C. Holmberg, V. Pascual
date2020-09 streamIETF areaart wgsipcore statusPROPOSED STANDARD pages15 canonicalhttps://www.rfc-editor.org/rfc/rfc8898 doi10.17487/RFC8898 errataview
This document defines the "Bearer" authentication scheme for the Session Initiation Protocol (SIP) and a mechanism by which user authentication and SIP registration authorization is delegated to a third party, using the OAuth 2.0 framework and OpenID Connect Core 1.0. This document updates RFC 3261 to provide guidance on how a SIP User Agent Client (UAC) responds to a SIP 401/407 response that contains multiple WWW-Authenticate/Proxy-Authenticate header fields.

updates