Re: [Dime] Comments on draft-ietf-dime-erp-03.txt

Qin Wu <sunseawq@huawei.com> Thu, 11 March 2010 06:27 UTC

Return-Path: <sunseawq@huawei.com>
X-Original-To: dime@core3.amsl.com
Delivered-To: dime@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 918FD3A6B08 for <dime@core3.amsl.com>; Wed, 10 Mar 2010 22:27:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.626
X-Spam-Level:
X-Spam-Status: No, score=-0.626 tagged_above=-999 required=5 tests=[AWL=-0.131, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IyqYhWlpNViU for <dime@core3.amsl.com>; Wed, 10 Mar 2010 22:27:04 -0800 (PST)
Received: from szxga02-in.huawei.com (unknown [119.145.14.65]) by core3.amsl.com (Postfix) with ESMTP id EB90D3A6B3A for <dime@ietf.org>; Wed, 10 Mar 2010 22:21:31 -0800 (PST)
Received: from huawei.com (szxga02-in [172.24.2.6]) by szxga02-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KZ300FNFTMMUX@szxga02-in.huawei.com> for dime@ietf.org; Thu, 11 Mar 2010 14:20:46 +0800 (CST)
Received: from huawei.com ([172.24.2.119]) by szxga02-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KZ300GTNTMMF2@szxga02-in.huawei.com> for dime@ietf.org; Thu, 11 Mar 2010 14:20:46 +0800 (CST)
Received: from w53375 ([10.164.12.38]) by szxml04-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTPA id <0KZ30035OTMLSR@szxml04-in.huawei.com> for dime@ietf.org; Thu, 11 Mar 2010 14:20:46 +0800 (CST)
Date: Thu, 11 Mar 2010 14:20:45 +0800
From: Qin Wu <sunseawq@huawei.com>
To: Glen Zorn <gwz@net-zen.net>, dime@ietf.org
Message-id: <064b01cac0e2$fc28e1c0$260ca40a@china.huawei.com>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.3350
X-Mailer: Microsoft Outlook Express 6.00.2900.3598
Content-type: text/plain; charset="iso-8859-1"
Content-transfer-encoding: 7bit
X-Priority: 3
X-MSMail-priority: Normal
References: <001501cac04d$390cdec0$ab269c40$@net>
Subject: Re: [Dime] Comments on draft-ietf-dime-erp-03.txt
X-BeenThere: dime@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Diameter Maintanence and Extentions Working Group <dime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dime>
List-Post: <mailto:dime@ietf.org>
List-Help: <mailto:dime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Mar 2010 06:27:05 -0000

> Section 4 says:
>   When an ER server receives the ERP/DER message, it searches its local
>   database for a root key
> 
>   FFS:
>      and authorization state?

[Qin]: I guess we talk this before as one of open issue. Seems authorization attributes 
is missing, such as 
1.how the service type and Authorization-Lifetime is configured, 
2.how to verify the local ER server is authorized to advertise the domain name, 
3.how to authorize those users for ERP service.
On the other hand, we should decouple authorization with authentication.

> There seems to be some confusion here: an ER server will _never_ receive an
> ERP/DER message, since that is a _Diameter_ message, not an EAP message.
> Actually, the confusion starts in the Introduction: "a new Diameter ERP
> application to transport ERP messages between an ER authenticator and the ER
> server".  "Authenticator" is a technical term & refers to an EAP protocol
> entity, not a Diameter entity, so how can send Diameter messages?  Clearing
> up this confusion might go a long way toward making an acceptable
> specification.

[Qin]: Is it a big issue?

_______________________________________________
> DiME mailing list
> DiME@ietf.org
> https://www.ietf.org/mailman/listinfo/dime