RE: RE: channel binding
From: Salowey, Joe (jsaloweycisco.com)
Date: Thu, 25 Aug 2005 23:57:18 -0400 (EDT)
 

> -----Original Message-----
> From: Jari Arkko [mailto:jari.arkko [at] piuha.net] 
> Sent: Thursday, August 25, 2005 4:43 AM
> To: Salowey, Joe
> Cc: Yoshihiro Ohba; Nicolas.Williams [at] sun.com; eap [at] frascone.com
> Subject: Re: [eap] RE: channel binding
> 
> Salowey, Joe wrote:
> 
> >>OK.  I think we are reaching some agreement on (please 
> correct if I'm
> >>wrong):
> >>
> >>- Channel binding mechanism in EAP-IKEv2 should not be removed (but 
> >>needs some modification to carry a blob in order to avoid the IANA 
> >>assignment issue.)
> >>
> >>- Key-derivation based channel binidng solution should be 
> specified as 
> >>an extension to EAP keying framework.
> >>
> >>    
> >>
> >
> >[Joe] Yes, I think this is a good approach.
> >  
> >
> Hold it. Does this mean that we'll have two (possibly
> incompatible) ways of doing channel bindings for, say, 
> wireless LAN access?
> 
[Joe] I don't think so. It lower layer that needs to coordinate this,
since it will specify what data either needs to go into the method, come
out of the method or bind to the keying material.  These approaches
provide tools for binding additional data to the authentication and/or
the key derivation, a lower layer would have to specify how to use them.



> --jari
> 

Results generated by Tiger Technologies using MHonArc.