RE: RE: channel binding
From: Charles Clancy (clancycs.umd.edu)
Date: Tue, 16 Aug 2005 14:18:36 -0400 (EDT)
On Fri, 12 Aug 2005, Salowey, Joe wrote:

OK. I think we are reaching some agreement on (please correct if I'm wrong):

- Channel binding mechanism in EAP-IKEv2 should not be removed (but needs some modification to carry a blob in order to avoid the IANA assignment issue.)

- Key-derivation based channel binidng solution should be specified as an extension to EAP keying framework.


[Joe] Yes, I think this is a good approach.

I concur. I'm planning to add channel binding support to EAP-PAX.


In a perfect world, I think it should be done within EAP itself. However, I think implementation changes make this an unrealistic for deployment in the forseeable future. Consequently, methods should continue providing this functionality until it can be moved to a more appropriate place.

[ t. charles clancy ]--[ tcc [at] umd.edu ]--[ www.cs.umd.edu/~clancy ]
[ computer science ]-----[ university of maryland | college park ]

Results generated by Tiger Technologies using MHonArc.