Re: RE: channel binding
From: Nicolas Williams (Nicolas.Williamssun.com)
Date: Thu, 11 Aug 2005 15:40:35 -0400 (EDT)
On Thu, Aug 11, 2005 at 07:05:11PM +0000, Yoshihiro Ohba wrote:
> >From: Nicolas Williams <Nicolas.Williams [at] sun.com>
> >Date: Wed, 10 Aug 2005 14:41:25 -0500
> 
> >But thinking of the SECMECH BoF GUAM proposal I do agree that the core
> >of a mechanism could/can/should indeed be specified such that it
> >provides only the fundamental properties needed and the rest of the EAP
> >or GSS semantics can then be provided by inclusion or elsewhere.
> 
> OK.  I think we are reaching some agreement on (please correct if I'm 
> wrong):
> 
> - Channel binding mechanism in EAP-IKEv2 should not be removed (but needs 
> some 
> modification to carry a blob in order to avoid the IANA assignment issue.)
> 
> - Key-derivation based channel binidng solution should be specified as an 
> extension to 
> EAP keying framework.

I'm a bit of a neutral party in this, so far.  You'll want to see what
Joe and the rest of the EAP community have to say.  Going by what Joe
has written already I think that only proposals involving changes to
specs that have not been implemented and deployed have a chance of
producing consensus.

Nico
-- 

Results generated by Tiger Technologies using MHonArc.