RE: RE: [eap] Issue 204: Peer-to-peer operation
From: Bernard Aboba (bernardawindows.microsoft.com)
Date: Tue, 2 Dec 2003 22:22:49 -0600 (CST)
Title: [802.1] RE: [eap] Issue 204: Peer-to-peer operation
Hope everyone had a joyous thanksgiving holiday. 
 
To clarify, Issue 204 was filed against the EAP State Machine document in order to address a problem in the EAP authenticator state machine pointed out in the resolution of Comment 15 on the IEEE 802.1aa D7.1 ballot. The EAP issues list is available here:
http://www.drizzle.com/~aboba/EAP/eapissues.html
 
The EAP WG discussion of Issue 204 is available starting here:
http://mail.frascone.com/pipermail/public/eap/2003-November/001896.html
 
The resolution to Issue 15 pointed out an asymmetry in the operation of a pass-through authenticator and a non-passthrough authenticator with respect to peer-to-peer operation.  Since in EAP the two cases are supposed to behave identically with respect to the on-the-wire protocol, this is believed to represent a bug in the operation of the authenticator state machine, as well as a potential difficiency in AAA, which may require the definition of a new attribute.  
 
A proposed fix to the EAP authenticator SM which would also affect the 802.1X/EAP state machine interface, is available here:
 
RFC 2284bis sections 2.3 and 2.4 were posted to the list for reference purposes, since they discuss the authenticator pass-through model and peer-to-peer operation in general, even they do not discuss the authenticator state machine or the proposed fixes to it. The entire text of RFC 2284bis-07 (which has now completed IETF last call) is available for inspection here:
 
http://www.ietf.org/internet-drafts/draft-ietf-eap-rfc2284bis-07.txt
 
 
 
 

Results generated by Tiger Technologies using MHonArc.