Re: [Emu] EAP and authorization
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Emu] EAP and authorization



Alper Yegin wrote:
> I’m not against this. But let’s face it, this is venturing into dealing
> with authorization parameters with EAP (EAP layer? EAP method layer?
> Etc.) I’m not against that either. In fact, I know there are a lot of
> people who’d be happy to see that happen.

  Prior to authentication, EAP is the only communications protocol
between a supplicant and *anywhere* on the network.  It is therefore
natural to overload it as a general purpose transport protocol.

> So, my question is, is this what we are doing: Enabling EAP to exchange
> authorization parameters among the EAP peer – authenticator –
> authentication server? If not, I hope someone can explain how this is
> different than what it takes to solve channel binding problem.

  I believe that is what is happening: authorization parameters are
being exchanged in EAP.  This should be made clearer in the documents.

  Alan DeKok.

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.