Re: [Dime] [HOKEY] DiME ERP: new Application ID or not ?(non-roaming case)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Dime] [HOKEY] DiME ERP: new Application ID or not ?(non-roaming case)



Hi Julien, 

>Hi hannes,
>
>On Thu, Mar 12, 2009 at 10:13 AM, Hannes Tschofenig 
><Hannes.Tschofenig at gmx.net> wrote:
>>
>>> 1/ re-uses full EAP authentication with Diameter EAP
>>
>>> 2/ perform a reauthentication using ERP.
>>
>>> If we use 2/, and we have a new Diameter ERP app-id, a distinct AAA 
>>>server may be reached.
>>
>> If I understood Glen correctly from previous conversations then the 
>> Diameter ERP re-authentication does not happen with a AAA server but 
>> with a HOKEY server. Hence, I am not sure that there is an issue.
>
> yes, you're right. But for me a HOKEY server is like an EAP 
>server. It may be collocated or not with a AAA server but the 
>NAS uses Diameter protocol so the message is a AAA message 
>which is going to reach a AAA server (colocated or not with an 
>HOKEY server).
Maybe that's just a terminology issue but it causes confusion regarding the
way how the messages are routed. 
In DIME we had this discussion regarding the routing of messages and Glen
clarified these aspects. 

I would also think it is extremely important to put a sort of architecture
picture in the Diameter ERP document that illustrates how the messages are
routed and how the entities relate to each other so that we aren't always
talking past each other. 

Ciao
Hannes

>
> Not that I was not pointing this as an issue.
>
>
> Regards,
>
> Julien
>
>>
>> Ciao
>> Hannes
>>
>>
>


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.