Re: [Dime] [HOKEY] DiME ERP: new Application ID or not ?(non-roamingcase)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Dime] [HOKEY] DiME ERP: new Application ID or not ?(non-roamingcase)
I agree, to my knowledge, the hokey server plays the AAA part. In the RFC 5296, it should be ER server for ERP if my understanding is correct.
----- Original Message -----
From: "Julien Bournelle" <julien.bournelle at gmail.com>
To: "Qin Wu" <sunseawq at huawei.com>
Cc: "Hannes Tschofenig" <Hannes.Tschofenig at gmx.net>; "Glen Zorn" <glenzorn at comcast.net>; <dime at ietf.org>; <hokey at ietf.org>
Sent: Thursday, March 12, 2009 5:53 PM
Subject: Re: [HOKEY] [Dime] DiME ERP: new Application ID or not ?(non-roamingcase)
Hi Qin,
On Thu, Mar 12, 2009 at 10:30 AM, Qin Wu <sunseawq at huawei.com> wrote:
> Hi:
> If my understanding is correct, the ERP re-authentication with a AAA server through a Hokey server will happen in the intial EAP exchange or in the bootstrapping phase.
> e.g., when the peer firstly enter into one visited AAA domain away from the home AAA server, intial EAP exchange between the peer and home AAA server is required. However when the peer move between two adjacent authenticator within the same AAA domain, the ERP re-authentication does not happen with a AAA server but with a local hokey server which is a optimized approach to reduce handoff latency.
hmm, same comment as for hannes. The local hokey server has a AAA
part (colocated or not). We are using a AAA protocol between the NAS
and the HOKEY server, so by extension, the HOKEY server as a AAA part
(colocated or not).
Regards,
Julien
>
> Best Regards!
> -Qin
> ----- Original Message -----
> From: "Hannes Tschofenig" <Hannes.Tschofenig at gmx.net>
> To: "'Julien Bournelle'" <julien.bournelle at gmail.com>; "'Qin Wu'" <sunseawq at huawei.com>
> Cc: "'Glen Zorn'" <glenzorn at comcast.net>; <dime at ietf.org>; <hokey at ietf.org>
> Sent: Thursday, March 12, 2009 5:13 PM
> Subject: RE: [HOKEY] [Dime] DiME ERP: new Application ID or not ?(non-roaming case)
>
>
>>
>>> 1/ re-uses full EAP authentication with Diameter EAP
>>
>>> 2/ perform a reauthentication using ERP.
>>
>>> If we use 2/, and we have a new Diameter ERP app-id, a
>>>distinct AAA server may be reached.
>>
>> If I understood Glen correctly from previous conversations then the Diameter
>> ERP re-authentication does not happen with a AAA server but with a HOKEY
>> server. Hence, I am not sure that there is an issue.
>>
>> Ciao
>> Hannes
>>
>
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.