RE: Question on EAP statemachine
From: Pasi.Eronen (Pasi.Eronennokia.com)
Date: Wed, 29 Jun 2005 09:55:21 -0400 (EDT)
Mahesh,

Negotiating the use of EAP and triggering the start of an EAP
conversation happens in the lower layer outside EAP, so it's
really beyond the scope of the peer state machine.

But I don't think there's anything in draft-ietf-eap-statemachine 
that would prevent a lower layer from having several separate EAP 
conversations, either in sequence like (in PANA), or in parallel 
(in which case you need multiple "instances" of the state machine).

Best regards,
Pasi

> -----Original Message-----
> From: ext Mahesh Kelkar [mailto:mkelkar [at] rocketmail.com]
> Sent: Wednesday, June 29, 2005 4:39 PM
> To: Eronen Pasi (Nokia-NRC/Helsinki); eap [at] frascone.com
> Subject: RE: Question on EAP statemachine
> 
> 
> Pasi,
> 
> Sorry about that; by EAP-start I meant the first EAP
> request packet originating from the backend authetntication
> server (assuming that authenticator & backend
> authentication servers are different & EAP-server resides
> on the backend authetnication server). Ex. EAP-TLS sets the
> start bit of the first EAP-TLS packet and hence I used the
> name EAP-start packet.
> 
> I was trying to elaborate the defintion of EAP conversation
> and wanted to get some feedback on it. 
> 
> I wanted to find out if we can negotiate EAP twice (or
> multiple times, one after the other and not the
> simultaneous). Does peer statemachine support that? Can we
> use different authentication methods for each EAP
> negotiation.? etc. 
> 
> Thanks
> Mahesh
> 
> --- Pasi.Eronen [at] nokia.com wrote:
> 
> > Hi,
> > 
> > There is no such thing as an "EAP-start" packet in EAP.
> > 802.1X does have an EAPOL-Start packet, but it is sent 
> > by the 802.1X supplicant (peer); RADIUS (RFC3579) has
> > an EAP-Start message, but it is sent by the RADIUS
> > client.
> > 
> > How multiple EAP conversations are handled depends a lot
> > on the lower layer in question. For instance, PANA has 
> > explicit support for two separate EAP conversations.
> > 
> > Best regards,
> > Pasi
<snip>

Results generated by Tiger Technologies using MHonArc.