RE: Proposed Resolution to Issue 323: AAA Key Cache
From: Bernard Aboba (bernard_abobahotmail.com)
Date: Tue, 10 Jan 2006 13:58:10 -0800 (PST)
1)Why do we mean by "existing implementations" and why does it matter?

The focus of this work item is on describing the behavior of RFC 3748, 4072 and 3579 implementations.


This document should provide requirements going forward. Is "caching
MSK/EMSK" a MUST NOT, a SHOULD NOT, or something else?

Caching of MSK/EMSK is a MUST NOT for RFC 4072 and 3579 implementations.


2) The text requires deleting of a key (I am assuming this includes
AMSK) after transport to avoid key reuse.

The text refers to any key that is transported, so yes it would also apply to an AMSK. This follows from the security assumptions and AAA Key Management requirements. Unless those requirements are met, this document will not be approved by the IESG.




Results generated by Tiger Technologies using MHonArc.