| Re: RE: channel binding | <– Date –> <– Thread –> |
|
From: Jari Arkko (jari.arkko |
|
| Date: Fri, 26 Aug 2005 02:55:12 -0400 (EDT) | |
Salowey, Joe wrote:
But I could have misunderstood what you meant.
--Jari
-----Original Message-----[Joe] I don't think so. It lower layer that needs to coordinate this,
From: Jari Arkko [mailto:jari.arkko [at] piuha.net] Sent: Thursday, August 25, 2005 4:43 AM
To: Salowey, Joe
Cc: Yoshihiro Ohba; Nicolas.Williams [at] sun.com; eap [at] frascone.com
Subject: Re: [eap] RE: channel binding
Salowey, Joe wrote:
correct if I'mOK. I think we are reaching some agreement on (please
specified aswrong):
- Channel binding mechanism in EAP-IKEv2 should not be removed (but needs some modification to carry a blob in order to avoid the IANA assignment issue.)
- Key-derivation based channel binidng solution should be
Hold it. Does this mean that we'll have two (possiblyan extension to EAP keying framework.[Joe] Yes, I think this is a good approach.
incompatible) ways of doing channel bindings for, say, wireless LAN access?
since it will specify what data either needs to go into the method, come
out of the method or bind to the keying material. These approaches
provide tools for binding additional data to the authentication and/or
the key derivation, a lower layer would have to specify how to use them.
I think I understand what you are saying. But does that mean that what you want is a set of tools that can be used by lower layers, but not a "ready made" solution that would work over existing link layers as-is? Or are you referring to AAA as the lower layer here? Certainly the AAA logic needs to be involved in any of the approaches that we've discussed. But it seems that in order to get an actual working channel binding solution, provide interoperability and maybe even media independence, its necessary to define the whole process, and not just tools.
But I could have misunderstood what you meant.
--Jari
- Re: Re: Channel Binding, (continued)
- Re: Re: Channel Binding Yoshihiro Ohba, August 25 2005
- Re: Re: Channel Binding Jari Arkko, August 25 2005
- Re: RE: channel binding Jari Arkko, August 25 2005
- Re: channel binding Yoshihiro Ohba, August 29 2005
Results generated by Tiger Technologies using MHonArc.