Re: [radext] #170: Allowed-Called-Station-Id usage scenarios
"radext issue tracker" <trac+radext@trac.tools.ietf.org> Sun, 20 October 2013 21:32 UTC
Return-Path: <trac+radext@trac.tools.ietf.org>
X-Original-To: radext@ietfa.amsl.com
Delivered-To: radext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5A75411E8292 for <radext@ietfa.amsl.com>; Sun, 20 Oct 2013 14:32:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.88
X-Spam-Level:
X-Spam-Status: No, score=-101.88 tagged_above=-999 required=5 tests=[AWL=0.719, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MCaStqZknC20 for <radext@ietfa.amsl.com>; Sun, 20 Oct 2013 14:32:53 -0700 (PDT)
Received: from grenache.tools.ietf.org (grenache.tools.ietf.org [IPv6:2a01:3f0:1:2::30]) by ietfa.amsl.com (Postfix) with ESMTP id 3E56111E8444 for <radext@ietf.org>; Sun, 20 Oct 2013 14:32:50 -0700 (PDT)
Received: from localhost ([127.0.0.1]:34707 helo=grenache.tools.ietf.org ident=www-data) by grenache.tools.ietf.org with esmtp (Exim 4.80) (envelope-from <trac+radext@trac.tools.ietf.org>) id 1VY0c6-0005R5-1u; Sun, 20 Oct 2013 23:32:42 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: radext issue tracker <trac+radext@trac.tools.ietf.org>
X-Trac-Version: 0.12.3
Precedence: bulk
Auto-Submitted: auto-generated
X-Mailer: Trac 0.12.3, by Edgewall Software
To: draft-ietf-radext-ieee802ext@tools.ietf.org, bernard_aboba@hotmail.com
X-Trac-Project: radext
Date: Sun, 20 Oct 2013 21:32:41 -0000
X-URL: http://tools.ietf.org/radext/
X-Trac-Ticket-URL: http://trac.tools.ietf.org/wg/radext/trac/ticket/170#comment:1
Message-ID: <081.c12eaf68c72597f1e514f0f325d42d6d@trac.tools.ietf.org>
References: <066.8c6dadfe7b14348ea276155a3c7ba51e@trac.tools.ietf.org>
X-Trac-Ticket-ID: 170
In-Reply-To: <066.8c6dadfe7b14348ea276155a3c7ba51e@trac.tools.ietf.org>
X-SA-Exim-Connect-IP: 127.0.0.1
X-SA-Exim-Rcpt-To: draft-ietf-radext-ieee802ext@tools.ietf.org, bernard_aboba@hotmail.com, radext@ietf.org
X-SA-Exim-Mail-From: trac+radext@trac.tools.ietf.org
X-SA-Exim-Scanned: No (on grenache.tools.ietf.org); SAEximRunCond expanded to false
Resent-To: bernard_aboba@hotmail.com, j@w1.fi, jsalowey@cisco.com, mark@azu.ca, paul_congdon@hp.com
Resent-Message-Id: <20131020213251.3E56111E8444@ietfa.amsl.com>
Resent-Date: Sun, 20 Oct 2013 14:32:50 -0700
Resent-From: trac+radext@trac.tools.ietf.org
Cc: radext@ietf.org
Subject: Re: [radext] #170: Allowed-Called-Station-Id usage scenarios
X-BeenThere: radext@ietf.org
X-Mailman-Version: 2.1.12
Reply-To: radext@ietf.org
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/radext>, <mailto:radext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/radext>
List-Post: <mailto:radext@ietf.org>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/radext>, <mailto:radext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 20 Oct 2013 21:32:54 -0000
#170: Allowed-Called-Station-Id usage scenarios Comment (by bernard_aboba@hotmail.com): Some clean up of the proposed text for Section 2.1: 2.1. Allowed-Called-Station-Id Description The Allowed-Called-Station-Id Attribute allows the RADIUS server to specify the authenticator MAC addresses and/or networks to which the user is allowed to connect. One or more Allowed-Called- Station-Id attributes MAY be included in an Access-Accept, CoA- Request or Accounting-Request packet. The Allowed-Called-Station-Id Attribute can be useful in situations where pre-authentication is supported (e.g. IEEE 802.11 pre-authentication). In these scenarios, a Called-Station- Id Attribute typically will not be included within the Access- Request so that the RADIUS server will not know the network that the user is attempting to access. The Allowed-Called-Station-Id enables the RADIUS server to restrict the networks and attachment points to which the user can subsequently connect. A summary of the Allowed-Called-Station-Id Attribute format is shown below. The fields are transmitted from left to right. 0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ | Type | Length | String... +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ Code TBD1 Length >=3 String The String field is one or more octets, specifying a Called- Station-Id that the user MAY connect to; if the Called-Station-Id that the user connects to does not match one of the Allowed- Called-Station-Id Attributes, the Network Authentication Server (NAS) MUST NOT permit the user to access the network. In the case of IEEE 802, the Allowed-Called-Station-Id Attribute is used to store the Medium Access Control (MAC) address in ASCII format (upper case only), with octet values separated by a "-". Example: "00-10-A4-23-19-C0". Where restrictions on both the network and authenticator MAC address usage are intended, the network name MUST be appended to the authenticator MAC address, separated from the MAC address with a ":". Example: "00-10-A4-23-19-C0:AP1". Where no MAC address restriction is intended, the MAC address field MUST be omitted, but ":" and the network name field MUST be included. Example: ":AP1". Within IEEE 802.11 [IEEE-802.11], the SSID constitutes the network name; within IEEE 802.1X [IEEE-802.1X], the Network-Id Name (NID- Name) constitutes the network name. Since a NID-Name can be up to 253 octets in length, when used with [IEEE-802.1X], there may not be sufficient room within the Allowed-Called-Station-Id Attribute to include both a MAC address and a Network Name. However, since the Allowed-Called-Station-Id Attribute is expected to be used largely in wireless access scenarios, this restriction is not considered serious. -- -------------------------------------+------------------------------------- Reporter: | Owner: draft-ietf-radext- bernard_aboba@hotmail.com | ieee802ext@tools.ietf.org Type: defect | Status: new Priority: minor | Milestone: milestone1 Component: ieee802ext | Version: 1.0 Severity: In WG Last Call | Resolution: Keywords: | -------------------------------------+------------------------------------- Ticket URL: <http://trac.tools.ietf.org/wg/radext/trac/ticket/170#comment:1> radext <http://tools.ietf.org/radext/>
- [radext] #170: Allowed-Called-Station-Id usage sc… radext issue tracker
- Re: [radext] #170: Allowed-Called-Station-Id usag… radext issue tracker
- Re: [radext] #170: Allowed-Called-Station-Id usag… radext issue tracker