Re: [MEXT] Well-known problem with authentication/etc. in wirelessnetworks
"Charles E. Perkins" <charliep@computer.org> Thu, 25 August 2011 16:27 UTC
Return-Path: <charliep@computer.org>
X-Original-To: mext@ietfa.amsl.com
Delivered-To: mext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
with ESMTP id 02C1F21F86AF for <mext@ietfa.amsl.com>;
Thu, 25 Aug 2011 09:27:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5
tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kuNviWLJP+wd for
<mext@ietfa.amsl.com>; Thu, 25 Aug 2011 09:27:06 -0700 (PDT)
Received: from elasmtp-galgo.atl.sa.earthlink.net
(elasmtp-galgo.atl.sa.earthlink.net [209.86.89.61]) by ietfa.amsl.com
(Postfix) with ESMTP id 197FD21F852E for <mext@ietf.org>;
Thu, 25 Aug 2011 09:27:06 -0700 (PDT)
Received: from [138.111.58.2] (helo=[172.17.96.89]) by
elasmtp-galgo.atl.sa.earthlink.net with esmtpsa (TLSv1:AES256-SHA:256) (Exim
4.67) (envelope-from <charliep@computer.org>) id 1Qwcmv-000237-Dx;
Thu, 25 Aug 2011 12:28:17 -0400
Message-ID: <4E56781E.60904@computer.org>
Date: Thu, 25 Aug 2011 09:28:14 -0700
From: "Charles E. Perkins" <charliep@computer.org>
Organization: Wichorus Inc.
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64;
rv:6.0) Gecko/20110812 Thunderbird/6.0
MIME-Version: 1.0
To: Alper Yegin <alper.yegin@yegin.org>
References: <4E554BAA.9080409@computer.org>
<82040B86-84C1-4CDD-B739-AC4D91865744@yegin.org>
In-Reply-To: <82040B86-84C1-4CDD-B739-AC4D91865744@yegin.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-ELNK-Trace: 137d7d78656ed6919973fd6a8f21c4f2d780f4a490ca6956d5d4673fe7faad8695c57ea4dfa317a4b19f31265620d5fe350badd9bab72f9c350badd9bab72f9c
X-Originating-IP: 138.111.58.2
Cc: mext <mext@ietf.org>
Subject: Re: [MEXT] Well-known problem with authentication/etc. in
wirelessnetworks
X-BeenThere: mext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: charliep@computer.org
List-Id: Mobile IPv6 EXTensions WG <mext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mext>,
<mailto:mext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mext>
List-Post: <mailto:mext@ietf.org>
List-Help: <mailto:mext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mext>,
<mailto:mext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Aug 2011 16:27:07 -0000
Hello Alper,
Here is a diagram that might help.
AS == Authentication server (AAA server)
AR == AAA relay
EA == EAP authenticator
UE == User Equipment == mobile node
== access terminal == ...
Then,
UE --- EA --- AS is a schematic diagram for 802.1x
We can have AAA relays:
UE --- EA --- AR --- AS
I can't think of any reason not to allow
HA as AR in this protocol exchange. And
then as part of the protocol operation the
home agent should be very simply able to
update its binding cache.
But this is just one example, using 802.1x.
Of course others are possible and important
in various circumstances. Why aren't we
there in all of those circumstances?
In the above diagram, we might also design EAP
signaling for mutual authentication in a single
round trip. Why not? If EAP is the magic
incantation that makes operators comfortable,
why not use it?
Regards,
Charlie P.
On 8/25/2011 1:48 AM, Alper Yegin wrote:
> Hi Charlie,
>
> On Aug 24, 2011, at 10:06 PM, Charles E. Perkins wrote:
>
>> If the Home Agent were recognized as a robust security
>> appliance, then it could naturally sit on the network
>> boundary as an IP-addressable device. Mobile IP
>> authentication could become the primary means of
>> validating user access, instead of an afterthought
>> to enable IP-address preservation after all the heavy
>> lifting has been done a lower levels.
>
> Do you mean using Mobile IP protocol for (local area) network access
> authentication? Or, something else?
>
> Alper
>
>
>
>
> _______________________________________________
> MEXT mailing list
> MEXT@ietf.org
> https://www.ietf.org/mailman/listinfo/mext
- [MEXT] Well-known problem with authentication/etc… Charles E. Perkins
- Re: [MEXT] Well-known problem with authentication… Alper Yegin
- Re: [MEXT] Well-known problem with authentication… Charles E. Perkins
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Pete McCann
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Charles E. Perkins
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Alper Yegin
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Pete McCann
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Basavaraj.Patil
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Pete McCann
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Charles E. Perkins
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Jong-Hyouk Lee
- Re: [MEXT] Well-known problem with authentication… Basavaraj.Patil
- Re: [MEXT] Well-known problem with authentication… Basavaraj.Patil
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Basavaraj.Patil
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Pete McCann
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Pete McCann
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Pete McCann
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Charles E. Perkins
- Re: [MEXT] Well-known problem with authentication… Basavaraj.Patil
- Re: [MEXT] Well-known problem with authentication… Charles E. Perkins
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Basavaraj.Patil
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Charles E. Perkins
- Re: [MEXT] Well-known problem with authentication… Basavaraj.Patil
- Re: [MEXT] Well-known problem with authentication… Julien Laganier
- Re: [MEXT] Well-known problem with authentication… Hesham Soliman
- Re: [MEXT] doubting a 3GPP MIP, because requires … Alexandru Petrescu
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Charles E. Perkins
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Charles E. Perkins
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Behcet Sarikaya
- Re: [MEXT] [!! SPAM] Re: Well-known problem witha… Charles E. Perkins
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Julien Laganier
- Re: [MEXT] [!! SPAM] Re: Well-known problem with … Pete McCann