| RE: Separation of EAP authenticator and AAA client | <– Date –> <– Thread –> |
|
From: Bernard Aboba (aboba |
|
| Date: Wed, 29 Jun 2005 00:22:52 -0400 (EDT) | |
> I guess an explicit NAS-ID needs to be carried by the EAP lower layer > unless we assume an implicit value (e.g., the MAC address of the 802.11 > AP). I think the authenticator identity needs to be explicitly defined. It could just be the MAC address but without defining it you get interoperability problems. > As we have discussed in EAP WG, the EAP peer and server are the > principals in an EAP conversation, and they do not utilize the > authenticator identity except as an opaque blob for channel bindings. > > They do not utilize peer and AAA server identities either. EAP methods do export the Peer-ID and the Server-ID, so I'm not sure what you mean. > Unless the NAS ports can convey the NAS-ID to the peer before secure > associations, NAS should also explicitly convey the port IDs in order to > provide the key cache boundary. What do you think? The lower layer spec needs to explicitly define the key scope/authenticator identity. Typically this is either an address of some kind (e.g. MAC address) or an identifier (NAS-ID). A port-ID is neither here nor there -- it doesn't tell the peer if the key derived on port X is also usable when connecting to port Y.
-
Separation of EAP authenticator and AAA client Bernard Aboba, June 27 2005
-
RE: Separation of EAP authenticator and AAA client Alper Yegin, June 28 2005
- RE: Separation of EAP authenticator and AAA client Bernard Aboba, June 28 2005
- RE: Separation of EAP authenticator and AAA client Alper Yegin, June 29 2005
- Message not available
- Re: RE: Separation of EAP authenticator and AAA client Bernard Aboba, June 28 2005
-
RE: Separation of EAP authenticator and AAA client Alper Yegin, June 28 2005
-
RE: Separation of EAP authenticator and AAA client Sood, Kapil, June 28 2005
- RE: Separation of EAP authenticator and AAA client Bernard Aboba, June 28 2005
Results generated by Tiger Technologies using MHonArc.