Return-path: <owner-radiusext@ops.ietf.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
 by megatron.ietf.org with esmtp (Exim 4.43) id 1JAhoP-0006IZ-7l
 for radext-archive-IeZ9sae2@lists.ietf.org; Fri, 04 Jan 2008 03:21:53 -0500
Received: from psg.com ([147.28.0.62])
 by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1JAhoO-0001ax-Ue
 for radext-archive-IeZ9sae2@lists.ietf.org; Fri, 04 Jan 2008 03:21:53 -0500
Received: from majordom by psg.com with local (Exim 4.68 (FreeBSD))
 (envelope-from <owner-radiusext@ops.ietf.org>) id 1JAhli-0009Am-UF
 for radiusext-data@psg.com; Fri, 04 Jan 2008 08:19:06 +0000
X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on psg.com
X-Spam-Level: 
X-Spam-Status: No, score=-2.2 required=5.0 tests=AWL,BAYES_00,RDNS_NONE,
 STOX_REPLY_TYPE autolearn=no version=3.2.3
Received: from [65.54.246.141] (helo=bay0-omc2-s5.bay0.hotmail.com)
 by psg.com with esmtp (Exim 4.68 (FreeBSD))
 (envelope-from <bernard_aboba@hotmail.com>) id 1JAhlg-0009AW-A6
 for radiusext@ops.ietf.org; Fri, 04 Jan 2008 08:19:05 +0000
Received: from BAY117-DS3 ([207.46.8.30]) by bay0-omc2-s5.bay0.hotmail.com
 with Microsoft SMTPSVC(6.0.3790.3959); 
 Fri, 4 Jan 2008 00:19:00 -0800
X-Originating-IP: [71.222.88.226]
X-Originating-Email: [bernard_aboba@hotmail.com]
Message-ID: <BAY117-DS3708A3269C29B41536BD3934C0@phx.gbl>
From: <Bernard_Aboba@hotmail.com>
In-Reply-To: <tslabo4d851.fsf@mit.edu>
 <BAY117-W1792E6240C29062FF9B6F2935F0@phx.gbl> <47729414.9070608@nitros9.org>
 <BAY117-DS17BF5949D5EDD59B29614935B0@phx.gbl> <47737D1C.5050208@nitros9.org>
 <00b101c84e5c$f7e0c600$e7a25200$@net> <477D6E52.60602@nitros9.org>
 <00f001c84e6f$1b0e5680$512b0380$@net> <477DE7C1.3080209@nitros9.org>
To: "Alan DeKok" <aland@nitros9.org>,
	"Glen Zorn" <glenzorn@comcast.net>
Cc: <radiusext@ops.ietf.org>
References: <tslabo4d851.fsf@mit.edu>
 <BAY117-W1792E6240C29062FF9B6F2935F0@phx.gbl> <47729414.9070608@nitros9.org>
 <BAY117-DS17BF5949D5EDD59B29614935B0@phx.gbl> <47737D1C.5050208@nitros9.org>
 <00b101c84e5c$f7e0c600$e7a25200$@net> <477D6E52.60602@nitros9.org>
 <00f001c84e6f$1b0e5680$512b0380$@net> <477DE7C1.3080209@nitros9.org>
Subject: Re: E2E and crypto-agility
X-Unsent: 1
Date: Fri, 4 Jan 2008 00:19:11 -0800
MIME-Version: 1.0
Content-Type: text/plain; format=flowed; charset="iso-8859-1";
 reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 12.0.1606
X-MimeOLE: Produced By Microsoft MimeOLE V12.0.1606
X-OriginalArrivalTime: 04 Jan 2008 08:19:00.0426 (UTC)
 FILETIME=[759672A0:01C84EAA]
Sender: owner-radiusext@ops.ietf.org
Precedence: bulk
X-Spam-Score: -2.3 (--)
X-Scan-Signature: 856eb5f76e7a34990d1d457d8e8e5b7f

>  I see no problem here.  e2e encryption is useful, and there are
> multiple methods where this can be done to *improve* security without
> making it perfect.

The question that is before the WG is "is support for e2e encryption a 
requirement for RADIUS crypto-agility?"

I think that this question is related to the automated key management 
question, because if we say that it is a requirement, then we have an
n x n problem that would seem to fall into the RFC 4107 requirements
for automated key management. 

 

--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>


