RE: Re: Issue 360: EMSK Transport
From: Bernard Aboba (bernard_abobahotmail.com)
Date: Tue, 2 May 2006 16:24:33 -0700 (PDT)
I'm ok with this.

From: "Salowey, Joe" <jsalowey [at] cisco.com>
To: "Narayanan, Vidya" <vidyan [at] qualcomm.com>, "Bernard Aboba" <bernard_aboba [at] hotmail.com>, <eap [at] frascone.com>
Subject: RE: [eap] Re: Issue 360: EMSK Transport
Date: Tue, 2 May 2006 13:50:49 -0700


The document should not discuss where the EMSK is exported to from the
EAP method as this may be implementation dependent.

Here is some suggested text (should go in 1.4 instead of section 2).

"The EMSK MUST NOT be provided to an entity outside the EAP server or
   peer,  nor is it permitted to pass any quantity to an entity outside
   the EAP server or peer from which the EMSK could be computed without
   breaking some cryptographic assumption, such as inverting a one-way
   function.  The EMSK MUST NOT be transported outside the EAP Server
   by the AAA layer.  As noted in [RFC3748] Section 7.10:"

Joe



Results generated by Tiger Technologies using MHonArc.