Re: Strawman -10
From: Jari Arkko (jari.arkkopiuha.net)
Date: Tue, 7 Feb 2006 05:55:02 -0800 (PST)
Bernard Aboba wrote:

The channel-binding draft allows KDF to be provided by an EAP method
while still satisfying the requirements of mode independence.


Do we really want to require EAP methods to support KDFs in order to enable the lower layer to generate keys from the EMSK? That would mean that existing EAP methods wouldn't be usable on some lower layers. One of the major advantages of EAP is the ability to support many lower layers.

What Joe proposes does not lead to that problem. He said "default + optional negotiation ability in methods".

Also, lower layer usage of EAP keys != EMSK usage. All current link layers
use MSK. If the link layers want to do link-layer specific things, they already
can. Why would we want to introduce another quantity to do the same thing?


--Jari


Results generated by Tiger Technologies using MHonArc.