Issue: section 2.1 AAA key caching
From: Salowey, Joe (jsaloweycisco.com)
Date: Tue, 2 May 2006 14:18:13 -0700 (PDT)
Submitter name: Joe Salowey
Submitter email address: jsalowey [at] cisco.com
Date first submitted: 05/02/06
Reference: 
Document: Keying Framework
Comment type:  T
Priority:  2  
Section: 2.1
Rationale/Explanation of issue:

The Current draft states that keys may not be cached once transported. I
am wondering if this is too restrictive.  Perhaps keys will be cached
for session recovery and availability purposes.  

Suggested Text:

 "In order to avoid key reuse, the AAA layer SHOULD delete transported
  keys once they are sent.  The AAA layer SHOULD NOT retain keys that
  it has previously sent.  For example, a AAA layer that has
  transported the MSK SHOULD delete it.  If the AAA layer does cache an
MSK
  then the use of TSKs derived from the MSK MUST prevent key reuse. "


Results generated by Tiger Technologies using MHonArc.