| Re: [Issue 248] Comments on EAP state machine v4 | <– Date –> <– Thread –> |
|
From: John Vollbrecht (jrv |
|
| Date: Thu, 22 Jul 2004 14:37:54 -0400 (EDT) | |
--On Friday, July 16, 2004 12:22 PM -0400 Nick Petroni <npetroni [at] cs.umd.edu> wrote:
.
.
.
I also think this would be a good recommendation, but not in the middle of the state machine. Perhaps in a EAP methods document would be better.> As a fall-back solution, I would recommend inserting something like the > following text advising that COND_SUCC may be dangerous: > > "In case the peer reaches the decision COND_SUCC, please note that the > peer is vulnerable to an active attacker that may easily lead him to > believe that the authenticator has reached any decision the attacker > chooses. In situations where security is a concern, it is RECOMMENDED to > avoid using the value COND_SUCC of the decision variable" This would be a good recommendation to method writers I think, but I am not sure a general claim about setting that variable alone is enough. We could add some guidelines for method authors in the Implementation Considerations section or perhaps better somewhere else? IMHO, the middle of the SM description is not the place to get into this.
_______________________________________________ eap mailing list eap [at] frascone.com http://mail.frascone.com/mailman/listinfo/eap
- Re: [Issue 248] Comments on EAP state machine v4, (continued)
- Re: [Issue 248] Comments on EAP state machine v4 Nick Petroni, July 16 2004
- Re: [Issue 248] Comments on EAP state machine v4 Jari Arkko, July 16 2004
- Re: [Issue 248] Comments on EAP state machine v4 Florent Bersani, July 17 2004
- Security considerations text in state machine draft (Was: Re: [eap] [Issue 248] Comments on EAP state machine v4) Jari Arkko, July 24 2004
- Re: [Issue 248] Comments on EAP state machine v4 John Vollbrecht, July 22 2004
- Re: [Issue 248] Comments on EAP state machine v4 Nick Petroni, July 16 2004
- Re: [Issue 248] Comments on EAP state machine v4 John Vollbrecht, July 22 2004
Results generated by Tiger Technologies using MHonArc.