Re: [Mipshop] RE: Review of draft-vidya-mipshop-handover-keys-aaa-00.txt
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Mipshop] RE: Review of draft-vidya-mipshop-handover-keys-aaa-00.txt
Narayanan Vidya-CVN065 wrote:
Why does the MN have to use PANA when it uses 802.11i for
network access? Why can't it just use the EAP method with the
handover key extension during 802.1x?
So, in this case, the AAA server will then send the MSK to the AP
and the HK to the AR? This is unlike the operation today where the
Does the AR need HK in the middle of a handover? Perhaps
we can do without it.
Why not let .11r (or something alike) handle re-authentication problem,
and assume that AR will forward the packets? At a less
critical time, the MN and AR can derive their HK again.
One of the key design goals in FMIP has been to disengage
all other signaling (e.g., RR, BU, DHCP in fmipv4) from
the critical path. We should try to preserve that as we
move along.
-Rajeev
AAA server does not send any keys unsolicited to an entity from which
it hasn't received any messages - isn't it?
_______________________________________________
Mipshop mailing list
Mipshop at ietf.org
https://www1.ietf.org/mailman/listinfo/mipshop
_______________________________________________
Mipshop mailing list
Mipshop at ietf.org
https://www1.ietf.org/mailman/listinfo/mipshop
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.