Re: Use of EMSK?
From: Julien Bournelle (julien.bournelleint-evry.fr)
Date: Thu, 6 Oct 2005 11:58:20 -0400 (EDT)
Hi all,

 I have a quick comment below:

On Thu, Oct 06, 2005 at 06:16:59PM +0300, Jari Arkko wrote:
> Bernard Aboba wrote:
> 
> >>From the point of view of the EAP Keying Framework, the AMSK is 
> >>calculated 
> >
> >in the lower layer.
> >
> >Therefore the issue is not how to calculate the AMSK, but how the NAS 
> >communicates that it wants/needs an AMSK, how legacy and upgraded AAA 
> >servers respond to that request, and what the structure of the AMSK 
> >cache is on the EAP peer, authenticator and AAA server.

 basically we had a use of AMSK for mip6 where the NAS(EAP
 authenticator) is not required
 to ask for the AMSK. Only the EAP client (MN) and AAA server (on which
 the EAP server is supposed to be colocated) needs to know that they should
 derive the AMSK. (This mip6-amsk is then provided to the HA.)

 As the i-d has expired, the draft can be found here:
 http://www.watersprings.org/pub/id/draft-giaretta-mip6-amsk-00.txt

 Maybe we're doing something wrong so any comments welcome.

> >
> >As far as I know, there is no document that answers these questions.
> 
> Right. Dave's proposal to use EMSK for purpose X would have to
> cover these issues.
> 
> --Jari
> 
> 
> _______________________________________________
> eap mailing list
> eap [at] frascone.com
> http://mail.frascone.com/mailman/listinfo/eap

-- 
julien.bournelle at int-evry.fr

Results generated by Tiger Technologies using MHonArc.