RE: Key derivation and the principle of equivalence
From: Bernard Aboba (abobainternaut.com)
Date: Fri, 13 May 2005 14:13:00 -0400 (EDT)
> [Joe] So I don't know that the authenticator identity is ever dealt with
> by EAP at all.

I don't think it is, except perhaps as part of an opaque Channel
Binding blob as Jari mentioned.

> It seems to be the server that is authenticated within
> EAP.  This should exported out of a method so a lower layer could use it
> for authorization.  A lower layer could also associate capabilites with
> a server identity as well.

Yes, the diagram shows the Server-ID being exported (if available).

Results generated by Tiger Technologies using MHonArc.