List Info

Thread: m.getKey() and RFC 4137




m.getKey() and RFC 4137
user name
2006-03-17 20:57:32
> > 
> 
> Vidya said:
> 
> "Are you saying then that in accordance with
4137, the EMSK 
> will also be delivered to the AAA layer on the EAP
server? "
> 
> That's how I read it, yes.  The keying material and 
> parameters are passed via the eapKeyData structure to
the 
> lower layer (which would be the AAA layer on the EAP
server 
> when in passthrough mode), via the m.getKey() function.
 The 
> AAA layer then fills in the aaaEapKeyData structure and

> passes this to the authenticator.  While both
eapKeyData and 
> aaaEapKeyData are of type "EAP Key" there
doesn't appear to 
> be a presumption that they are the same.  So the AAA
layer 
> could receive the EMSK, but not pass it to the
> authenticator.   
> 

I wonder if we are restricted in defining the behavior of
the EMSK based
on a spec that did not consider EMSKs to begin with? It may
be that we
would conclude it is okay to pass the EMSK to the AAA layer
- but,
should we be constrained by 4137 though? 

Vidya
____________________________________________________________
_____
To unsubscribe or modify your subscription options, please
visit:
http:/
/lists.frascone.com/mailman/listinfo/eap

Arhives: http://lists.
frascone.com/pipermail/eap
m.getKey() and RFC 4137
user name
2006-03-17 21:42:15
Vidya said:

"I wonder if we are restricted in defining the
behavior of the EMSK based
on a spec that did not consider EMSKs to begin with? It may
be that we
would conclude it is okay to pass the EMSK to the AAA layer
- but,
should we be constrained by 4137 though?" 

RFC 4137 treats keying material as a *structure* not a
single variable, so
that all the keying material and parameters are passed to
the lower layer at
the same time.  This would not have been necessary if the
document only
meant to deal with the MSK. Since RFC 4137 references the
key frame work
document as well as RFC 3748, it cannot be claimed that it
was unaware of
the key management document, which until -09 included
passing of the EMSK to
the lower layer. 

   

____________________________________________________________
_____
To unsubscribe or modify your subscription options, please
visit:
http:/
/lists.frascone.com/mailman/listinfo/eap

Arhives: http://lists.
frascone.com/pipermail/eap
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )