[Emu] draft-dekok-emu-eap-arpa-01 and WBA unauthenticated EAP-TLS

Heikki Vatiainen <hvn@radiatorsoftware.com> Mon, 18 March 2024 08:36 UTC

Return-Path: <hvn@radiatorsoftware.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 441DFC151990 for <emu@ietfa.amsl.com>; Mon, 18 Mar 2024 01:36:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.905
X-Spam-Level:
X-Spam-Status: No, score=-1.905 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=radiatorsoftware-com.20230601.gappssmtp.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VXbyD2AwrfF7 for <emu@ietfa.amsl.com>; Mon, 18 Mar 2024 01:36:15 -0700 (PDT)
Received: from mail-wr1-x42e.google.com (mail-wr1-x42e.google.com [IPv6:2a00:1450:4864:20::42e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4B169C151070 for <emu@ietf.org>; Mon, 18 Mar 2024 01:35:44 -0700 (PDT)
Received: by mail-wr1-x42e.google.com with SMTP id ffacd0b85a97d-33e570ef661so1700519f8f.1 for <emu@ietf.org>; Mon, 18 Mar 2024 01:35:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=radiatorsoftware-com.20230601.gappssmtp.com; s=20230601; t=1710750943; x=1711355743; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=wKNNkTwgcYLFggZJSxrXc3YhctMJMVSxTXl9RXpGcwA=; b=douLoCwr7ji/FKdHr30KBNaSkXCuuPiORtWq2Vj1QEVz4qMhO4dGbe6bKG/tqORyMB ObvU6lPWQiO85I58oVlZi+cmWn500i6+Lk3Btoit1a9jDRwP8uvbeqS53v+BsKrUhjSa tt9hnGt8w9MmHic3rHXq0ws/SWo/fQQ5S3MFWUHVFaLkbRRc79VvECtruTS4TNXz0vAS VjKIr+WjOXWJFNDlrQPTLZiSe495jfMVaKFqFM62zsCm+ikEq1XGdz+MqpjazAjH7NKB uU4b/d8nTdCiuXxDhNGo+j9By+kjBS7d7+fvPhh22V7gChAgRjR4V14Mt6/xp/Iqh2vh NILA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1710750943; x=1711355743; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=wKNNkTwgcYLFggZJSxrXc3YhctMJMVSxTXl9RXpGcwA=; b=P/Q524GZ0OiHNUeANUMAqVZeADbV0koRI87v7WiBIKWSnJrm3XjPjiiwN8tUAfWiTW BmTNM6DJy2PtYxUaEEaH9zfOb1NtTOQMIdFAQP8ySM2imfzjuT8AwOcRNA+5I9Ncm+vr YMLcpxszrwE7+birr4Z2oN49W1lKwZhkTA+HTFJJx00X+HFaZ4mgRDJQEWV3vl3sa+dy W6mHq4q7VrOYgmsKOeY2mE0cTlAlScpO2osE+2CdKw8WxQ13fRw9sflZMhG088uZMPAr 1ElwunjBW7UFshoBH7uwQ1xUIcdeGqxgDystZUXx6ZeA3c6Qtz5nEzrl4OdnQG3Kr55w 2QBw==
X-Gm-Message-State: AOJu0Yzc6eAhBKmhFlOJoBck2Esh4lIJE4GW2Nf0TL+oyNHnSIp+O+jZ NIPEFlPmCmjCGuljlXjpLo2fNAcJBexTsDhqE2OQVqn2A76Y8NAvwzSK5atWwFSsdNvywiiO5q4 dyHWIoENtKd0GwzaxR1fGLUuOn5pd0zeisHP2FPtPVnwMS9ErLg==
X-Google-Smtp-Source: AGHT+IG/I43XxSQ0m2dwbU8BX69MNMXf1vJ6yMcotwpxkFfOQH+rznRnZKLdqTVLZ3SdYOGHadf6jV8iFr5XQSPfWbk=
X-Received: by 2002:a5d:5051:0:b0:33e:aea8:6969 with SMTP id h17-20020a5d5051000000b0033eaea86969mr8755983wrt.27.1710750943013; Mon, 18 Mar 2024 01:35:43 -0700 (PDT)
MIME-Version: 1.0
From: Heikki Vatiainen <hvn@radiatorsoftware.com>
Date: Mon, 18 Mar 2024 18:35:26 +1000
Message-ID: <CAA7Lko8LPB0XV6g5kALvDyyThVgtgQYervG6iHRO133vPzBymA@mail.gmail.com>
To: EMU WG <emu@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000420adb0613eb3e51"
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/K4A89hTZnv_DmFPzpE_8iAMygn4>
Subject: [Emu] draft-dekok-emu-eap-arpa-01 and WBA unauthenticated EAP-TLS
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Mar 2024 08:36:19 -0000

Draft draft-dekok-emu-eap-arpa-01 has the following text:

https://www.ietf.org/archive/id/draft-dekok-emu-eap-arpa-01.html#section-4-3
  TBD: The Wireless Broadband Alliance (WBA) has defined an unauthenticated
  EAP-TLS method, using a vendor-specific EAP type. Get link.

This appears to be part of Hotspot 2.0r2 and wpa_supplicant implements it.
For example:
https://w1.fi/cgit/hostap/tree/src/eap_common/eap_defs.h#n112
https://w1.fi/cgit/hostap/tree/src/eap_server/eap_server_tls.c#n479

Wikipedia has more info about its history and pointers to the first commits
from 10+ years ago:
https://en.wikipedia.org/wiki/Extensible_Authentication_Protocol#EAP-TLS

I haven't seen any use of "WFA-UNAUTH-TLS", though.

-- 
Heikki Vatiainen
hvn@radiatorsoftware.com