[HOKEY] [Technical Errata Reported] RFC5296 (1825)

RFC Errata System <rfc-editor@rfc-editor.org> Tue, 11 August 2009 00:16 UTC

Return-Path: <web-usrn@ISI.EDU>
X-Original-To: hokey@core3.amsl.com
Delivered-To: hokey@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3C4E23A6F65 for <hokey@core3.amsl.com>; Mon, 10 Aug 2009 17:16:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -16.797
X-Spam-Level:
X-Spam-Status: No, score=-16.797 tagged_above=-999 required=5 tests=[AWL=0.802, BAYES_00=-2.599, USER_IN_DEF_WHITELIST=-15]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HudERem+ONNq for <hokey@core3.amsl.com>; Mon, 10 Aug 2009 17:16:52 -0700 (PDT)
Received: from boreas.isi.edu (boreas.isi.edu [128.9.160.161]) by core3.amsl.com (Postfix) with ESMTP id 5B1CE3A6F64 for <hokey@ietf.org>; Mon, 10 Aug 2009 17:16:52 -0700 (PDT)
Received: from boreas.isi.edu (localhost [127.0.0.1]) by boreas.isi.edu (8.13.8/8.13.8) with ESMTP id n7B0G8HW002058 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Mon, 10 Aug 2009 17:16:08 -0700 (PDT)
Received: (from web-usrn@localhost) by boreas.isi.edu (8.13.8/8.13.8/Submit) id n7B0G7mp002057; Mon, 10 Aug 2009 17:16:07 -0700 (PDT)
Date: Mon, 10 Aug 2009 17:16:07 -0700
Message-Id: <200908110016.n7B0G7mp002057@boreas.isi.edu>
To: vidyan@qualcomm.com, ldondeti@qualcomm.com, tim.polk@nist.gov, pasi.eronen@nokia.com, gwz@net-zen.net, tena@huawei.com
From: RFC Errata System <rfc-editor@rfc-editor.org>
X-ISI-4-43-8-MailScanner: Found to be clean
X-MailScanner-From: web-usrn@boreas.isi.edu
Cc: hokey@ietf.org, rfc-editor@rfc-editor.org
Subject: [HOKEY] [Technical Errata Reported] RFC5296 (1825)
X-BeenThere: hokey@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HOKEY WG Mailing List <hokey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hokey>
List-Post: <mailto:hokey@ietf.org>
List-Help: <mailto:hokey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Aug 2009 00:16:53 -0000

The following errata report has been submitted for RFC5296,
"EAP Extensions for EAP Re-authentication Protocol (ERP)".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=5296&eid=1825

--------------------------------------
Type: Technical
Reported by: Glen Zorn <gwz@net-zen.net>

Section: 5.1

Original Text
-------------
   We identify two types of bootstrapping for ERP: explicit and implicit
   bootstrapping.  In implicit bootstrapping, the local ER server SHOULD
   include its domain name and SHOULD request the DSRK from the home AAA
   server during the initial EAP exchange, in the AAA message
   encapsulating the first EAP Response message sent by the peer.

Corrected Text
--------------
   We identify two types of bootstrapping for ERP: explicit and implicit
   bootstrapping.  In implicit bootstrapping, the local AAA client or agent 
   SHOULD include its domain name and SHOULD request the DSRK from the home AAA
   server in the AAA message encapsulating the first EAP Response message sent
   by the peer during the initial EAP exchange.

Notes
-----
The local ER server is an ERP entity, incapable of inserting anything into a AAA message; the ER server's purpose is to provide reauthentication services, not to edit AAA messages.  Furthermore, the original text requires that the ER server unnecessarily insert itself in the path of EAP messages, slowing the initial authentication.

Instructions:
-------------
This errata is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party (IESG)
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC5296 (draft-ietf-hokey-erx-14)
--------------------------------------
Title               : EAP Extensions for EAP Re-authentication Protocol (ERP)
Publication Date    : August 2008
Author(s)           : V. Narayanan, L. Dondeti
Category            : PROPOSED STANDARD
Source              : Handover Keying
Area                : Security
Stream              : IETF
Verifying Party     : IESG