RE: Re: EAP Key Binding
From: Alper Yegin (alper.yeginsamsung.com)
Date: Wed, 20 Apr 2005 16:22:09 -0400 (EDT)
        The centralized model encourages AC implementations to use one
PMK 
        for many different WTPs. This practice facilitates speedy
transition 
        by a station from one WTP to another WTP that is connected to
the same 
        AC without establishing a separate PMK.  However, this leaves
the station 
        in a difficult position.  The station cannot distinguish between
a 
        compromised PMK and one that is intentionally being shared. This
issue must 
        be resolved, but the resolution is beyond the scope of the
CAPWAP working group.

So, the issue is about binding PMK to NAS ports (WTPs in this case).
Unless the NAS explicitly informs the host about the list of ports, how
can this be handled? I think this is an issue for the EAP lower layer to
handle.

Alper



Results generated by Tiger Technologies using MHonArc.