Re: Issue on eap-keying: naming of AMSks
From: Jari Arkko (jari.arkkopiuha.net)
Date: Tue, 5 Oct 2004 11:30:24 -0400 (EDT)
Florent Bersani wrote:

I agree. Perhaps we capture that in eap-keying. By including sth in the key naming section, saying that:
"It is RECOMMENDED that Applications use the key names defined in this document to refer to specific EAP Keying material, however applications may very well use their own naming scheme to refer to this keys"
Does that sound good?

Ok.



I'd favor #2
If we don't provide usable names. Applications will either define their own ones from scratch or hash ours (and make possibly some mistake here).
So I'd favor a 128 or 160 bit key name.

Fine with me!


--Jari

--Jari

It seems that the definition of the AMSK name may be up to the application
that is using the key. I suppose it is fine to define a name, but I'm not
sure it is good to expect application to use that name. This brings up
another topic. I think in many cases a fixed length name may be more useful
(perhaps this is an ID, who knows). The current naming schemes can lead to
long variable length names. I would rather (or also) like to see schemes
that result in a fixed length name (or ID).


eap-admin [at] frascone.com wrote:

Description of issue: should AMSK naming be mandatory?

Submitter name: Florent Bersani

Submitter email address: florent.bersani [at] francetelecom.com

Date first submitted: 10/04/2004

Document: Keying Framework

Comment type: 'E'ditorial

Priority: 1 should fix

Section: 2.4

Rationale/Explanation of issue:

section 2.4 reads: "AMSK Name

      AMSKs, if any, may be named by the concatenation of the string
      "AMSK", key label, application data (see Appendix F), and EMSK
Name."
However, I think it is sound practice to name keys. Since
AMSK are new,
we shouldn't be bothered with legacy reasons. Hence, why not
make this
AMSK naming "mandatory"



Requested change

Replace the previous text by
"AMSK Name

AMSKs, if any, are named by concatenating the string
"AMSK", key label, application data (see Appendix F), and EMSK
Name."









Results generated by Tiger Technologies using MHonArc.