Re: [Dime] Need to know the location of a roaming peer?
w52006 <w52006@huawei.com> Thu, 26 November 2009 01:07 UTC
Return-Path: <w52006@huawei.com>
X-Original-To: dime@core3.amsl.com
Delivered-To: dime@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AC3D43A680C for <dime@core3.amsl.com>; Wed, 25 Nov 2009 17:07:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.914
X-Spam-Level: *
X-Spam-Status: No, score=1.914 tagged_above=-999 required=5 tests=[AWL=2.409, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id raQsohFiHK14 for <dime@core3.amsl.com>; Wed, 25 Nov 2009 17:07:04 -0800 (PST)
Received: from szxga04-in.huawei.com (unknown [119.145.14.67]) by core3.amsl.com (Postfix) with ESMTP id 333853A67BD for <dime@ietf.org>; Wed, 25 Nov 2009 17:07:00 -0800 (PST)
Received: from huawei.com (szxga04-in [172.24.2.12]) by szxga04-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KTO00J46Z38KH@szxga04-in.huawei.com> for dime@ietf.org; Thu, 26 Nov 2009 09:06:44 +0800 (CST)
Received: from huawei.com ([172.24.2.119]) by szxga04-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0KTO00MRZZ383R@szxga04-in.huawei.com> for dime@ietf.org; Thu, 26 Nov 2009 09:06:44 +0800 (CST)
Received: from w52006e ([10.164.12.19]) by szxml06-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTPA id <0KTO00D1QZ380Z@szxml06-in.huawei.com> for dime@ietf.org; Thu, 26 Nov 2009 09:06:44 +0800 (CST)
Date: Thu, 26 Nov 2009 09:06:43 +0800
From: w52006 <w52006@huawei.com>
In-reply-to: <4B0232F5.3030805@nict.go.jp>
To: 'Sebastien Decugis' <sdecugis@nict.go.jp>, dime@ietf.org
Message-id: <00eb01ca6e34$b8493280$130ca40a@china.huawei.com>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.3350
X-Mailer: Microsoft Office Outlook 11
Content-type: text/plain; charset="us-ascii"
Content-transfer-encoding: 7bit
Thread-index: AcpnRkI6C9jvkrc8RnmJbRzPOwXXawG7ATEQ
Subject: Re: [Dime] Need to know the location of a roaming peer?
X-BeenThere: dime@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Diameter Maintanence and Extentions Working Group <dime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dime>
List-Post: <mailto:dime@ietf.org>
List-Help: <mailto:dime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dime>, <mailto:dime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Nov 2009 01:07:05 -0000
Hello Mostly I agree your concern too. Please see one comment as below... B.R. Yungui Wang > -----Original Message----- > From: dime-bounces@ietf.org [mailto:dime-bounces@ietf.org] On > Behalf Of Sebastien Decugis > Sent: Tuesday, November 17, 2009 1:22 PM > To: dime@ietf.org > Subject: [Dime] Need to know the location of a roaming peer? > > Hello all, > > During the last meeting (thanks Hannes and Jouni for the > minutes) there > was a discussion about the need (or absence of need) to > notify the home > domain when a peer changes its authenticator in a visited > domain. During > the discussion on ERP, my understanding of the conclusion was that we > should do the re-authentication locally when possible in the visited > domain, without going back to home domain. > Then, in case new > authorization attributes are needed, we have a separate exchange with > the home realm to fetch these fresh authorization attributes, > after the authentication is performed. As described In section 5.3 of RFC5296, the realm part of keyName-NAI is the local (ER server's) domain name. How can the new NAS know that the authorization attributes should be freshed to the home server? Does other entity (e.g. the ER server) do? In addition, when the peer moves to the new NAS, the old NAS should delete the original authentication session with the home server. In this way, is it acceptable for home server without peer's authentication session while new authorization session is freshed/reserved? > > Later during the session, a remark on emergency services (related to > Diameter Parameter Query draft if I am not mistaken) sent the question > back on the table, highlighting that in some contexts we may want to > query the home server for the current location of the user. I am > wondering, if the peer can move without the home server being notified > (we assume server-initiated messages are routed transparently to the > correct recipient) then the design of such query mechanism will be > affected and complexity added. > > I would like to ask the list if there is strong concerns with "hiding" > the current authenticator of a roaming user to the home server, the > result being that the home realm only knows the current > location with a > granularity of the realm (inter-realm handovers should still > have to go > to the home realm, AFAIU). > > PS: I am wondering, in the context of emergency services, if we are > really interested by the authenticator or by the point of > attachment for > the given peer, as I understand there is a difference in some > deployment > schemes... > > Thank you for any comment, > > Best regards, > Sebastien. > > -- > Sebastien Decugis > Research fellow > Network Architecture Group > NICT (nict.go.jp) > > _______________________________________________ > DiME mailing list > DiME@ietf.org > https://www.ietf.org/mailman/listinfo/dime >