Re: [88attendees] WPA2 Enterprise WiFi?

joel jaeggli <joelja@gmail.com> Fri, 08 November 2013 20:01 UTC

Return-Path: <joelja@gmail.com>
X-Original-To: 88attendees@ietfa.amsl.com
Delivered-To: 88attendees@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 62B1C11E81CF for <88attendees@ietfa.amsl.com>; Fri, 8 Nov 2013 12:01:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hh3jPr7TePHi for <88attendees@ietfa.amsl.com>; Fri, 8 Nov 2013 12:01:10 -0800 (PST)
Received: from mail-pb0-x233.google.com (mail-pb0-x233.google.com [IPv6:2607:f8b0:400e:c01::233]) by ietfa.amsl.com (Postfix) with ESMTP id 1E13D11E81B4 for <88attendees@ietf.org>; Fri, 8 Nov 2013 12:01:02 -0800 (PST)
Received: by mail-pb0-f51.google.com with SMTP id xa7so2609430pbc.10 for <88attendees@ietf.org>; Fri, 08 Nov 2013 12:00:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=content-type:mime-version:subject:from:in-reply-to:date:cc :message-id:references:to; bh=Psv6iVxQs7O2BO0scACo3moodEXQzROS6XzK6YvZvqI=; b=UrdKLrKHi+VfoWCdY/j4thqAfW+GU+W8W33ZOb6W3Cs0dlrMxT/IGoVFfp/z3Zu+Pj LryEtweY8WdgpbKAaZMt0yrTwq0ZYAXJjpmDhJrlpAVc8IfcBGvZwvzk3eWxio9FeIcf McAWqnAyfS+pJilIbv2j5voQ8sVsagmf3jVueS2B2t/J0uB5nznFvZ/ji+8VlgVEtnA4 Fa8tzGtyGxn8s/jHsSVhwlmJRPn5RiebXRd3WF2yKSFoIvGR6Kc3FkTkqH1ZDr7aS/3p WHMdq/N1w0Kis0W7jzH52y9kzjIkYDRtHe5WkKIJgtLJhXdBLoS5EP52/xvahaq71ySw gwXg==
X-Received: by 10.66.190.198 with SMTP id gs6mr17275401pac.49.1383940858374; Fri, 08 Nov 2013 12:00:58 -0800 (PST)
Received: from dhcp-bc20.meeting.ietf.org (dhcp-bc20.meeting.ietf.org. [31.133.188.32]) by mx.google.com with ESMTPSA id nj9sm13947518pbc.13.2013.11.08.12.00.56 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 08 Nov 2013 12:00:57 -0800 (PST)
Content-Type: multipart/signed; boundary="Apple-Mail=_DA9CE38D-6D03-453E-84DC-6CC8731498F9"; protocol="application/pgp-signature"; micalg="pgp-sha1"
Mime-Version: 1.0 (Mac OS X Mail 7.0 \(1816\))
From: joel jaeggli <joelja@gmail.com>
In-Reply-To: <527D3AB4.40600@sidn.nl>
Date: Fri, 08 Nov 2013 12:00:54 -0800
Message-Id: <0E3993B6-CBCF-467B-B5D6-A0BCE581FBD4@gmail.com>
References: <527D3AB4.40600@sidn.nl>
To: "Marco Davids (SIDN)" <marco.davids@sidn.nl>
X-Mailer: Apple Mail (2.1816)
Cc: "88attendees@ietf.org" <88attendees@ietf.org>
Subject: Re: [88attendees] WPA2 Enterprise WiFi?
X-BeenThere: 88attendees@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Mailing list of IETF 88 attendees that have opted in to the list." <88attendees.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/88attendees>, <mailto:88attendees-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/88attendees>
List-Post: <mailto:88attendees@ietf.org>
List-Help: <mailto:88attendees-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/88attendees>, <mailto:88attendees-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Nov 2013 20:01:11 -0000

On Nov 8, 2013, at 11:25 AM, Marco Davids (SIDN) <marco.davids@sidn.nl> wrote:

> Hi,
> 
> Now, I'm not an expert on the matter, but since privacy seems to be the
> major theme of this 88th IETF, I was wondering; would it be of any value
> if we introduce WPA2 Enterprise (WPA-802.1X mode) in the WiFi network ?
> 

wpa2 enterprise is in fact deployed at the IETF.

ietf.1x and ietf-a.1x

The radius server that supports the .1x ssids accepts any credentials as valid.

> Logging in with personal credentials seems a bit more secure in terms of
> 'privacy’.

not using credentials at all and still getting perfect forward security seems better.

> 

> The IETF could send them to me, PGP-encrypted, next time I register and
> upload my PGP-key on the website, for example.

I wouldn’t mind getting the cert fingerprint signed in a mail I have to accept it on faith the first time around.

> 
> Regards,
> 
> -- 
> Marco
> _______________________________________________
> 88attendees mailing list
> 88attendees@ietf.org
> https://www.ietf.org/mailman/listinfo/88attendees