RE: Re: issue 357: Channel Binding Definition
From: Bernard Aboba (bernard_abobahotmail.com)
Date: Tue, 2 May 2006 12:23:18 -0700 (PDT)
That makes sense. Do we also need to indicate that the channel bindings need to be the same for all parties? For example:

"Channel Binding

A secure mechanism for ensuring the synchronization and correctness of channel properties
(such as endpoint identifiers) provided to the EAP peer, authenticator and server."


Minor clarification:

"Channel Binding

A *secure* mechanism for ensuring the correctness of channel properties
(such as endpoint identifiers) provided to the EAP peer, authenticator
and server. "

The word secure is to imply that if this data is in fact sent as a blob
between the peer and server, it must be integrity protected.

Vidya



Results generated by Tiger Technologies using MHonArc.