Re: PANA and EAP keying framework
From: Yoshihiro Ohba (yohbatari.toshiba.com)
Date: Tue, 10 Jan 2006 13:45:12 -0800 (PST)
On Tue, Jan 10, 2006 at 01:05:01PM -0800, Bernard Aboba wrote:
> >In any case, another way is to use multiple (virtual) APs, one
> >operating in 'open' authentication running PANA and the other
> >operating in 802.11i, and switching from the former AP to the latter
> >after PANA authentication.
> 
> That is also forbidden in IEEE 802.11i, which includes the authorizations 
> as part of the PMKSA context.  Therefore it is not permitted to use 
> authorizations provided for one virtual AP with another virtual AP.

The authorization provided for the 'open' authentication AP is given
free regardless of the PANA authentication result (the authoriation
for this AP is given even before starting PANA authentication).  On
the other hand, the authorization provided for other APs are given
only after successful PANA authentication.  So I don't understand what
is the issue here.

Yoshihiro Ohba

Results generated by Tiger Technologies using MHonArc.