Autoprov hardening

Description

When autoprovisioning is enabled the anonymous endpoint allow people to register as an anonymous peer.

An attacker can the brute force the autoprov code. The attacker will not get a valid username or password while doing that but it could consume resources in case of a ddos and it fill the asterisk log files and console
with failed dial attempts.

Zendesk Ticket IDs

None

Activity

Show:
Done

Details

Priority

Assignee

Reporter

Approvers

François Blackburn

Fix versions

Sprint

Zendesk Support

Created November 21, 2018 at 8:06 PM
Updated January 18, 2019 at 3:38 PM
Resolved December 5, 2018 at 1:44 PM