Re: Key derivation and the principle of equivalence
From: Jari Arkko (jari.arkkopiuha.net)
Date: Fri, 13 May 2005 03:32:39 -0400 (EDT)
Bernard Aboba wrote:

I think we need to be clear about which layer learns this information.
The EAP method layer is aware of the identities provided in the
EAP-Response/Identity but according to RFC 3748 should be using its own
method-specific identities instead; these are exported as the Peer-ID and
Server-ID.  From the perspective of EAP, I think those are the only
relevant identities.

It is the EAP lower layer that is aware of the authenticator identity
because this identity is only communicated at the lower layer.  The
diagram doesn't describe the Authenticator-Identity as being passed to the
EAP method, and existing methods wouldn't make use of it, so I'm assuming
that the EAP method doesn't obtain this or care about it.



Yes, you are right. The EAP method may in some cases
transport information about these, but if it does, it should
do it so as opaque data.

--Jari



Results generated by Tiger Technologies using MHonArc.