RE: channel binding
From: Salowey, Joe (jsaloweycisco.com)
Date: Wed, 31 Aug 2005 23:16:20 -0400 (EDT)
> I have a doubt about applicability of keyed MAC for a blob in 
> three-party key management system.  If the keyed MAC is 
> generated by peer and authenticator, and the authenticator 
> sends the MAC to the server (via a AAA protocol), which key 
> is used for MAC computation? 

[Joe] OK I think I see the misunderstanding.  The Keyed MAC is
transmitted as part of the Method between the EAP-Peer and the
EAP-Server.  The authenticator is not involved directly. 

> Note that AAA-Key is not used in this case because AAA-Key is 
> not yet available at the authenticator before the 
> authenticator sends the MAC to the server, for all possible 
> solutions we have discussed.
> 
> Yoshihiro Ohba
> 
> 
> > 
> > [ t. charles clancy ]--[ tcc [at] umd.edu ]--[ 
> www.cs.umd.edu/~clancy ] [ 
> > computer science ]-----[ university of maryland | college park ]
> 

Results generated by Tiger Technologies using MHonArc.