channel binding consensus call
From: Jari Arkko (jari.arkkopiuha.net)
Date: Thu, 25 Aug 2005 08:27:21 -0400 (EDT)
In IETF-63 we discussed different ways of achieving channel
bindings, but we also got requirements from methods authors
that a solution is needed so that they can include/reference
it in their specifications and analysis. In the SECMECH BoF
there were also comments made that the channel binding
functionality is essential.

In the last couple of weeks there's been a discussion
about the pros and cons of the two proposed schemes.
Before continuing that discussion, I'd like to take a step
back and first make the decision that we'll actually be
working on some solution, and some of the key requirements
for the solution. This will also confirm the consensus that
we had in Paris for not developing such a solution to the keying
framework.

So here are the questions:

1. Should we take on a WG work item, a specification
   of a solution/protocol that provides channel bindings?

2. Is this solution something that should go to
   keying framework, as "the" mechanism to be
   used by everyone, or is it an independent
   extension? Result from Paris, at least as far
   as Yoshi's scheme goes, was "independent
   extension".

3. Should the solution be unified in some sense
   across different types of EAP usage or should
   we pursue multiple approaches? An example
   of multiple approaches would be leaving it
   to individual method writes without coordination,
   different mechanisms for different link layers,
   or developing both method and aaa-key based
   mechanisms.

Please answer by Wednesday, August 31st.

--Jari


Results generated by Tiger Technologies using MHonArc.