Re: [AAA-WG]: Wrapping up Diameter EAP...

Yoshihiro Ohba <yohba@tari.toshiba.com> Wed, 12 May 2004 16:13 UTC

Received: from trapdoor.merit.edu (postfix@trapdoor.merit.edu [198.108.1.26]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA22352 for <aaa-archive@lists.ietf.org>; Wed, 12 May 2004 12:13:45 -0400 (EDT)
Received: by trapdoor.merit.edu (Postfix) id 249629127E; Wed, 12 May 2004 12:13:30 -0400 (EDT)
Delivered-To: aaa-wg-outgoing@trapdoor.merit.edu
Received: by trapdoor.merit.edu (Postfix, from userid 56) id E428C9127F; Wed, 12 May 2004 12:13:29 -0400 (EDT)
Delivered-To: aaa-wg@trapdoor.merit.edu
Received: from segue.merit.edu (segue.merit.edu [198.108.1.41]) by trapdoor.merit.edu (Postfix) with ESMTP id 89AA09127E for <aaa-wg@trapdoor.merit.edu>; Wed, 12 May 2004 12:13:27 -0400 (EDT)
Received: by segue.merit.edu (Postfix) id 71A6659136; Wed, 12 May 2004 12:13:27 -0400 (EDT)
Delivered-To: aaa-wg@merit.edu
Received: from inet-tsb.toshiba.co.jp (inet-tsb.toshiba.co.jp [202.33.96.40]) by segue.merit.edu (Postfix) with ESMTP id 7B208590E9 for <aaa-wg@merit.edu>; Wed, 12 May 2004 12:13:26 -0400 (EDT)
Received: from tsb-wall.toshiba.co.jp ([133.199.160.134]) by inet-tsb.toshiba.co.jp with ESMTP id i4CGDLgH024679; Thu, 13 May 2004 01:13:21 +0900 (JST)
Received: (from root@localhost) by tsb-wall.toshiba.co.jp id i4CGDLeE013894; Thu, 13 May 2004 01:13:21 +0900 (JST)
Received: from tis2 [133.199.160.66] by tsb-wall.toshiba.co.jp with SMTP id BAA13892 ; Thu, 13 May 2004 01:13:21 +0900
Received: from mx.toshiba.co.jp by tis2.tis.toshiba.co.jp id BAA05247; Thu, 13 May 2004 01:13:20 +0900 (JST)
Received: from tsb-sgw.toshiba.co.jp by toshiba.co.jp id BAA11766; Thu, 13 May 2004 01:13:19 +0900 (JST)
Received: from tsbpo1.po.toshiba.co.jp by tsb-sgw.toshiba.co.jp with ESMTP id i4CGDJEU012870; Thu, 13 May 2004 01:13:19 +0900 (JST)
Received: from steelhead ([172.30.24.114]) by tsbpo1.po.toshiba.co.jp (Sun Internet Mail Server sims.3.5.1999.01.13.19.49.p4) with ESMTP id <0HXL00D89ZQ49G@tsbpo1.po.toshiba.co.jp>; Thu, 13 May 2004 01:13:18 +0900 (JST)
Received: from ohba by steelhead with local (Exim 3.36 #1 (Debian)) id 1BNwMl-0007Xc-00; Wed, 12 May 2004 09:13:55 -0700
Date: Wed, 12 May 2004 09:13:55 -0700
From: Yoshihiro Ohba <yohba@tari.toshiba.com>
Subject: Re: [AAA-WG]: Wrapping up Diameter EAP...
In-reply-to: <Pine.LNX.4.56.0405120741200.24794@internaut.com>
To: Bernard Aboba <aboba@internaut.com>
Cc: Pasi.Eronen@nokia.com, aaa-wg@merit.edu
Message-id: <20040512161355.GE25541@steelhead>
MIME-version: 1.0
Content-type: text/plain; charset="iso-2022-jp"
Content-disposition: inline
User-Agent: Mutt/1.5.5.1+cvs20040105i
References: <052E0C61B69C3741AFA5FE88ACC775A6010C3AA8@esebe023.ntc.nokia.com> <Pine.LNX.4.56.0405120741200.24794@internaut.com>
Sender: owner-aaa-wg@merit.edu
Precedence: bulk

On Wed, May 12, 2004 at 07:45:17AM -0700, Bernard Aboba wrote:
> A question:
> 
> RFC 3579 requires that a RADIUS client be able to differentiate one EAP
> session from another.  As we've been discussing in EAP WG, this may be
> tricky in the case where an EAP authentication is restarted via an
> EAPOL-Start message.
> 
> I don't see any text in this draft equivalent to RFC 3579, Section 2.6.1
> that describe how Diameter handles this problem.  I suspect that Diameter
> should be able to do better than RADIUS, but guidance on how the server
> should behave would be helpful.

Hmm, what is the exact definition of EAP session?

In section 4.1 of draft-ietf-eap-rfc2284bis-09.txt:

      "Since the Identifier space is unique to each session,
      authenticators are not restricted to only 256 simultaneous
      authentication conversations.  Similarly, with re-authentication,
      an EAP conversation might continue over a long period of time, and
      is not limited to only 256 roundtrips."

This text seems to indicate that an EAP session can span over multiple
rounds of re-authentication, and I don't think session identification
attributes do not have to change when reset or re-authentication
occurs.

Yoshihiro Ohba




> 
> On Wed, 12 May 2004 Pasi.Eronen@nokia.com wrote:
> 
> > Hi,
> >
> > I've posted an intermediate version of draft-ietf-aaa-eap-06.a
> > at http://www.cs.hut.fi/~peronen/eap/diameter_eap.html
> > together with a HTML diff from version -05.
> >
> > This is supposed to resolve all remaining open issues, but
> > I would encourage everyone to check if they are OK with
> > the changes.
> >
> > If I don't get any complaints, I'll post this as -06 some time
> > next week and ask the WG chairs to send it to the IESG.
> >
> > Best regards,
> > Pasi
> >