Re: Re: Issue 352: Channel Binding Issue
From: Yoshihiro Ohba (yohbatari.toshiba.com)
Date: Mon, 8 May 2006 13:09:10 -0700 (PDT)
On Mon, May 08, 2006 at 05:25:51PM +0300, Jari Arkko wrote:
> Yoshihiro Ohba wrote:
> 
> >On Tue, May 02, 2006 at 04:23:22PM -0700, Salowey, Joe wrote:
> >  
> >
> >>Hmmm... 
> >>
> >>Peer gets MSK from EAP and mixes it with Y to get MSKY 
> >>Authenticator gets mixed MSKY in exisitng AAA attribute, since this is
> >>an exisitng attribute it thinks it is just the MSK and mixes it with Y
> >>to get MSKYY.  MSKY and MSKYY don't match.
> >>    
> >>
> >
> >There is some misunderstanding.  If the authenticator is supposed to
> >further mix Y to get MSKYY from MSKY, then the peer is also supposed
> >to further mix Y to get MSKYY from MSKY.
> >  
> >
> Yes, but the question is how do the peer and the AAA server
> know that they are doing this? This is a change from the
> current procedures, so presumably to make this all work there
> needs to be negotiation somewhere that its turned on.

Yes, and this is described in the first bullet of Section 7 "EAP
Method Requirements" of draft-ohba-eap-channel-binding-00.txt.

Yoshihiro Ohba

Results generated by Tiger Technologies using MHonArc.