Re: [Emu] WG last call for draft-ietf-emu-tls-eap-types ?

Alan DeKok <aland@deployingradius.com> Wed, 21 September 2022 18:12 UTC

Return-Path: <aland@deployingradius.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0E36C14CE24 for <emu@ietfa.amsl.com>; Wed, 21 Sep 2022 11:12:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.909
X-Spam-Level:
X-Spam-Status: No, score=-6.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qb_dmol2eERz for <emu@ietfa.amsl.com>; Wed, 21 Sep 2022 11:12:42 -0700 (PDT)
Received: from mail.networkradius.com (mail.networkradius.com [62.210.147.122]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9573FC14F748 for <emu@ietf.org>; Wed, 21 Sep 2022 11:12:41 -0700 (PDT)
Received: from smtpclient.apple (135-23-95-173.cpe.pppoe.ca [135.23.95.173]) by mail.networkradius.com (Postfix) with ESMTPSA id AF18937; Wed, 21 Sep 2022 18:12:38 +0000 (UTC)
Authentication-Results: NetworkRADIUS; dmarc=none (p=none dis=none) header.from=deployingradius.com
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.120.41.1.1\))
From: Alan DeKok <aland@deployingradius.com>
In-Reply-To: <CAA7Lko8sn_VLxmPHBe6igeJ14_8Wwm9QdNhJDDvo6=EZTCFPXg@mail.gmail.com>
Date: Wed, 21 Sep 2022 14:12:37 -0400
Cc: Alexander Clouter <alex+ietf@coremem.com>, EMU WG <emu@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <DEB52F60-B090-4E1F-999F-CCDC80236392@deployingradius.com>
References: <325659CB-E36E-4D18-A59C-B5EA54324201@deployingradius.com> <CAOgPGoAYTe0qtFbJhq7S71FpX+k+1=0Gqqq+pwa+1QnBnQ3wrw@mail.gmail.com> <94154D9C-F880-42DB-B881-38B04F76E196@deployingradius.com> <CAOgPGoBF_8y40oynqQd9rr9PKEy1qNoNae3zMwA+7f7rKN+SUg@mail.gmail.com> <20220910075838.57qeco3egljt7pwp@aineko.digriz.org.uk> <CAA7Lko8sn_VLxmPHBe6igeJ14_8Wwm9QdNhJDDvo6=EZTCFPXg@mail.gmail.com>
To: Heikki Vatiainen <hvn@radiatorsoftware.com>
X-Mailer: Apple Mail (2.3696.120.41.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/4bL_tNl3Nz9XXCk4h8xNuhTgzcA>
Subject: Re: [Emu] WG last call for draft-ietf-emu-tls-eap-types ?
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Sep 2022 18:12:45 -0000

On Sep 21, 2022, at 1:56 PM, Heikki Vatiainen <hvn@radiatorsoftware.com> wrote:
> I can take a look at EAP-FAST server side implementation with updates to Radiator.

  That would be helpful.

> Patches pointed by [3] above are for TEAP,

  Those patches are to get TEAP working with TLS 1.2.  The basic TEAP implementation in hostap just didn't work. :(

> but if there's something that needs to be changed in hostapd for EAP-FAST, please let me know. A quick look shows that it may need something that's not available in its git repository yet.

  Yes.  The final TEAP patches also haven't been merged.

> Are there any other clients that could be used for testing? 

  I don't think so, unfortunately.  XSupplicant is long dead.  The OpenSea alliance helped with that, as did the authors moving on to other work.  There's iwd, but it doesn't implement TEAP or FAST.

  The supplicant landscape is unfortunately rather limited.

  Alan DeKok.