Re: [Dime] New draft for Diameter ERP: poll for adoption
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Dime] New draft for Diameter ERP: poll for adoption



Hi,

Qin Wu a écrit :
> [Qin]: As I discussed with Glen before, We recommend to use more generic new AVPs to accommodate all the key materials containing DSRK, MSK,rMSK.
>   
I see. I think we can re-use the EAP-Master-Session-Key existing AVP
container for transporting key material. I am not aware of any existing
AVP suitable for Lifetime and key name, but there are probably some
already (maybe in the RADIUS namespace). Then, creating a grouped AVP
including all these elements, plus optional others, for each purpose,
seems straightforward to me. Anyway, this can be discussed later, it's
not a fundamental design issue, IMHO.

> [Qin]: I am not sure. I think It needs to be further discussion.
>  In my mind, it is not clear whether we extend DER/DEA or define new Command Code to accommodate the two new EAP code,i.e.,EAP Initiate/Finish, as regarding key distribution between local server and home server, is it okay for us to reuse DER/DEA to transport the key to the right local server? We need to think about it.
>   
That is the main concern of this new draft. Diameter routing is based on
the application-id and destination-realm, not the command code. So
re-using DER/DEA or creating a new command code is not related to the
problem of routing the message to the proper server. For this purpose,
the draft creates a new application id (Diameter ERP).


> [Qin]: I'd be happy to contribute/co-author these drafts and support the work on this topic.
>   
Great, thank you :) Let's see what other people think...

Sebastien.

-- 
Sebastien Decugis
Research fellow
Network Architecture Group
NICT (nict.go.jp)


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.