Re: [HOKEY] draft-gaonkar-radext-erp-attrs-03

Bernard Aboba <bernard_aboba@hotmail.com> Thu, 13 March 2008 14:09 UTC

Return-Path: <hokey-bounces@ietf.org>
X-Original-To: ietfarch-hokey-archive@core3.amsl.com
Delivered-To: ietfarch-hokey-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E818428C948; Thu, 13 Mar 2008 07:09:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.128
X-Spam-Level:
X-Spam-Status: No, score=-100.128 tagged_above=-999 required=5 tests=[AWL=0.308, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_ORG=0.611, HTML_MESSAGE=0.001, RDNS_NONE=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rSTZOu37knYk; Thu, 13 Mar 2008 07:09:45 -0700 (PDT)
Received: from core3.amsl.com (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 333A528C9D2; Thu, 13 Mar 2008 07:08:49 -0700 (PDT)
X-Original-To: hokey@core3.amsl.com
Delivered-To: hokey@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2C5CF28C991 for <hokey@core3.amsl.com>; Thu, 13 Mar 2008 07:08:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R1TzZFCS-Odu for <hokey@core3.amsl.com>; Thu, 13 Mar 2008 07:08:46 -0700 (PDT)
Received: from blu139-omc2-s6.blu139.hotmail.com (blu139-omc2-s6.blu139.hotmail.com [65.55.175.176]) by core3.amsl.com (Postfix) with ESMTP id 3BD6A28C992 for <hokey@ietf.org>; Thu, 13 Mar 2008 07:07:28 -0700 (PDT)
Received: from BLU137-W1 ([65.55.162.186]) by blu139-omc2-s6.blu139.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Thu, 13 Mar 2008 07:05:10 -0700
Message-ID: <BLU137-W134FF79EC38D86A612ACB93090@phx.gbl>
X-Originating-IP: [130.129.20.161]
From: Bernard Aboba <bernard_aboba@hotmail.com>
To: "David B. Nelson" <dnelson@elbrysnetworks.com>, 'Glen Zorn' <glenzorn@comcast.net>, 'Lakshminath Dondeti' <ldondeti@qualcomm.com>
Date: Thu, 13 Mar 2008 07:05:10 -0700
Importance: Normal
In-Reply-To: <003f01c88496$97b60b30$091716ac@xpsuperdvd2>
References: <003601c88386$d06b7a20$091716ac@xpsuperdvd2> <47D69F03.3030800@qualcomm.com> <002401c88487$99e12660$091716ac@xpsuperdvd2> <001101c8848e$2e04ad20$2d01f00a@arubanetworks.com> <003f01c88496$97b60b30$091716ac@xpsuperdvd2>
MIME-Version: 1.0
X-OriginalArrivalTime: 13 Mar 2008 14:05:10.0377 (UTC) FILETIME=[3FF23590:01C88513]
Cc: hokey@ietf.org
Subject: Re: [HOKEY] draft-gaonkar-radext-erp-attrs-03
X-BeenThere: hokey@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HOKEY WG Mailing List <hokey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/hokey>
List-Post: <mailto:hokey@ietf.org>
List-Help: <mailto:hokey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hokey>, <mailto:hokey-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1828954270=="
Sender: hokey-bounces@ietf.org
Errors-To: hokey-bounces@ietf.org

> Why do you say that?  If we have Encrypted Attributes in RADIUS, surely that
> specifies an internal-to-RADIUS cryptographic protection mechanism.  Cannot
> the HOKEY Key Container attribute use the Encrypted Attribute format?

I don't see why this wouldn't work.  There might be some algorithm
considerations (for example, use of AES Keywrap with appropriate padding).  
_______________________________________________
HOKEY mailing list
HOKEY@ietf.org
https://www.ietf.org/mailman/listinfo/hokey