| RE: RE: [Isms] RADIUS is not a trusted third party | <– Date –> <– Thread –> |
|
From: Bernard Aboba (aboba |
|
| Date: Thu, 21 Apr 2005 22:59:51 -0400 (EDT) | |
> I think there is a subtle difference between a "trusted third party" and > a RADIUS server which may have bi-lateral trust relationships with > various parties. Yes. Where RADIUS proxies are present there is no trust relationship between the NAS and RADIUS server. This is in contrast to Diameter, where such a relationship can be established via re-direct. The distinction is important in a number of cases. In Kerberos, the KDC is able to provide a ticket to any principal because it has a shared secret that it shares with that principle. Within RADIUS this is not possible. A RADIUS server cannot provide the user with a ticket to a NAS because it may not have a trust relationship with that NAS. Note that at one point, there was a proposal for integration of RADIUS with Kerberos. That proposal did in fact enable RADIUS to become a true trusted third party. The proposal seemed practical. However, the AAA WG went with another proposal (Diameter CMS) which it turned out that noone wanted to implement. Among other things, the proposal enabled a RADIUS server to send a key to a NAS that could not be viewed by intervening proxies. In retrospect, the IETF may have missed an important opportunity. For a trip down memory lane, look here: http://www.watersprings.org/pub/id/draft-kaushik-radius-sec-ext-06.txt
- Re: RE: [Isms] RADIUS is not a trusted third party, (continued)
-
Re: RE: [Isms] RADIUS is not a trusted third party Jeff Mandin, April 20 2005
- RE: RE: [Isms] RADIUS is not a trusted third party Glen Zorn (gwz), April 20 2005
-
RE: RE: [Isms] RADIUS is not a trusted third party Nelson, David, April 21 2005
- Re: RE: [Isms] RADIUS is not a trusted third party John Vollbrecht, April 21 2005
- RE: RE: [Isms] RADIUS is not a trusted third party Bernard Aboba, April 21 2005
- Re: RE: [Isms] RADIUS is not a trusted third party Julien Bournelle, April 22 2005
- Re: RE: [Isms] RADIUS is not a trusted third party Bernard Aboba, April 22 2005
-
Re: RE: [Isms] RADIUS is not a trusted third party Jeff Mandin, April 20 2005
- Message not available
- Re: RE: [Isms] RADIUS is not a trusted third party Bernard Aboba, April 22 2005
Results generated by Tiger Technologies using MHonArc.