A comment on draft-groeting-eap-netselection-results-00.txt
From: Alper Yegin (alper.yeginsamsung.com)
Date: Tue, 20 Jul 2004 15:49:22 -0400 (EDT)
   The usage of EAP the Extensible Authentication Protocol in
   IEEE 802.1x/IEEE 802.11i or also PANA never aimed to allow
   authentication of the access network to the end host.

I think what we really care is the authorization: Is this NAS authorized
to serve the client for network access service? AS should make this
determination, looking at the ID of the NAS and authenticating it as a
part of the RADIUS/Diameter exchange.

At the end of the full round of AAA, NAS has the blessing of the AS. By
the virtue of having the right crypto key (AAA-Key), it can prove that
to the client as well. 

Alper



Results generated by Tiger Technologies using MHonArc.