RE: interpretation of the identity response
From: Bernard Aboba (abobainternaut.com)
Date: Wed, 29 Oct 2003 20:59:17 -0600 (CST)
> I think the processing of the identity response is up to the mechanism.
> If the NAI is decorated in non-standard means that is not known to the
> home AAA this can be a problem (it is also not within the NAI
> specification). Many mechanisms have a way to request or determine
> identity independent of the EAP identity response
> (EAP-SIM,EAP-AKA,EAP-TLS,EAP-MCSHAPv2).   I If I had my preference I
> would use the identity response for routing only and ignore the user
> identity in the identity response.  It should be a recommendation that
> mechanisms provide a way to obtain identity outside of the identity
> response.

Yes, I agree with this. A side benefit is that the Identity can be
protected.

Is there any text that needs to be added to RFC 2284bis to clarify this?
We're in IETF last call now, so I'd encourage submission of an issue...

Results generated by Tiger Technologies using MHonArc.