List Info

Thread: Revised resolution to Issue 372: Key Lifetime




Revised resolution to Issue 372: Key Lifetime
user name
2006-08-17 15:57:42
>   About section 3.6, it sounds fine. The authenticator
"reclaim[ing] 
>resources" is a bit unclear.
>   Also, deleting the older key first does not read to
me as the same as a 
>LIFO queue, as the last >   key to be added is the
newest one, and that's 
>not the one that it is thrown out first.
>   Michaela

How about this?

"3.6. Key cache Synchronization

Key lifetime negotiation alone cannot guarantee key cache
synchronization. Even where a lower layer exchange is run
immediately after EAP in order to determine the lifetime of
EAP
keying material, it is still possible for the authenticator
to
purge all or part of the key cache prematurely (e.g. due to
reboot or
need to reclaim memory).

The lower layer may utilize the Discovery phase 0 to improve
key
cache synchronization. For example, if the authenticator
manages the
key cache by deleting the oldest key first, the relative
creation time of the last key to be deleted could be
advertised
within the Discovery phase, enabling the peer to determine
whether
keying material had been prematurely expired from the
authenticator
key cache."


____________________________________________________________
_____
To unsubscribe or modify your subscription options, please
visit:
http:/
/lists.frascone.com/mailman/listinfo/eap

Arhives: http://lists.
frascone.com/pipermail/eap
Revised resolution to Issue 372: Key Lifetime
user name
2006-08-17 16:13:58
Sounds very clear now. Thanks.


Bernard Aboba <bernard_abobahotmail.com> wrote:
> About section 3.6, it sounds fine. The authenticator "reclaim[ing]
>resources" is a bit unclear.
&gt; Also, deleting the older key first does not read to me as the same as a
>LIFO queue, as the last > key to be added is the newest one, and that's
>not the one that it is thrown out first.
>; Michaela

How about this?

"3.6. Key cache Synchronization

Key lifetime negotiation alone cannot guarantee key cache
synchronization. Even where a lower layer exchange is run
immediately after EAP in order to determine the lifetime of EAP
keying material, it is still possible for the authenticator to
purge all or part of the key cache prematurely (e.g. due to reboot or
need to reclaim memory).

The lower layer may utilize the Discovery phase 0 to improve key
cache synchronization. For example, if the authenticator manages the
key cache by deleting the oldest key first, the relative
creation time of the last key to be deleted could be advertised
within the Discovery phase, enabling the peer to determine whether
keying material had been prematurely expired from the authenticator
key cache."




Talk is cheap. Use Yahoo! Messenger to make PC-to-Phone calls. Great rates starting at 1¢/min.
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )