Which RFC should I use to bring SHA1 and SHA2 authentication to RTSP 1.0?

Viewed 39

RTSP 1.0's RFC2326 uses RFC2617 for WWW Authentication, which is the same used for HTTP authentication. This 2617 is old and only covers MD5. I know that RTSP 2.0 is out but I'm working on 1.0. Lots of IP cameras still implement 1.0 only.

I guess some cameras might use SHA1. SHA2 might be too new, I don't know if they use but it's possible.

Which RFC should I read to bring SHA1 and possibly SHA2 to RTSP 1.0? Should I just use the latest WWW Authentication RFC, if such exists?

1 Answers

Actually, RFC 2326 predates RFC 2617, so pedantically speaking, it used an even older version of HTTP auth.

It appears you are interested in "Digest" authentication. The relevant spec for that nowadays is RFC 7616. It's supposed to be backwards-compatible, so I would recommend it as the definitive source.

Just be aware of the changes compared to older specs, which the devices you want to talk to might not implement: https://www.rfc-editor.org/rfc/rfc7616#appendix-A

Related