How to disable encryption for IMS AKA ?
Hello,
Due to requirements to VoLTE in some states (Australia, Japan, and others), no encrypthion shall be used during the security association setup process between UE and SBC, i.e Security-Server header field must have parameter ealg=null in first response 494/401 from SBC. I see that by default 'null' value is included into encryption algorithm list in the ims-aka-profile, which is used on access VoLTE sip-interface. But SBC anyway proposes to use the encryption in setup - it sends 494/401 with ealg=aes-cbc.
ims-aka-profile
name IMS_AKA_VoLTE_Profile
start-protected-client-port 4060
end-protected-client-port 4064
protected-server-port 4070
auth-alg-list hmac-sha-1-96 hmac-md5-96
encr-alg-list aes-cbc des-ede3-cbc