RE: [Issue 297] Review of Identity Selection -12
From: Bernard Aboba (abobainternaut.com)
Date: Mon, 25 Apr 2005 12:07:36 -0400 (EDT)
> section 5.1 says that proxy must reply with Access-Reject or
> Access-Challenge -- so why do you consider that additional proxy
> behavior?
> Thanks,
> Farid

RFC 2607 doesn't say what is contained in the Access-Reject (probably
because it was written before use of EAP became popular).  Back in those
days, an Access-Reject would probably just contain a Reply-Message
attribute with an error message, or maybe nothing at all.  However,
Reply-Message was deprecated in RFC 3579, so that won't work with EAP.

Therefore the portion of the document that refers to acceptable
proxy behavior in response to an unknown realm in an Access-Request
containing EAP-Message attributes probably should be followed by all
RADIUS proxies.  It's a clarification of RFC 2607 for use with EAP.

Results generated by Tiger Technologies using MHonArc.