Re: Manual network access logins (Was: Re: [RAM] The mapping problem: rendezvous points?)

Tony Li <tli@cisco.com> Tue, 22 May 2007 19:51 UTC

Return-path: <ram-bounces@iab.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1HqaOk-0006HE-AB; Tue, 22 May 2007 15:51:58 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HqaOd-0006H3-Es for ram@iab.org; Tue, 22 May 2007 15:51:51 -0400
Received: from sj-iport-4.cisco.com ([171.68.10.86]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HqaOc-0001kF-4n for ram@iab.org; Tue, 22 May 2007 15:51:51 -0400
Received: from sj-dkim-7.cisco.com ([171.68.10.88]) by sj-iport-4.cisco.com with ESMTP; 22 May 2007 12:51:44 -0700
X-IronPort-AV: i="4.14,567,1170662400"; d="scan'208"; a="1997360:sNHT21276720"
Received: from sj-core-3.cisco.com (sj-core-3.cisco.com [171.68.223.137]) by sj-dkim-7.cisco.com (8.12.11/8.12.11) with ESMTP id l4MJpiF3008278; Tue, 22 May 2007 12:51:44 -0700
Received: from xbh-sjc-231.amer.cisco.com (xbh-sjc-231.cisco.com [128.107.191.100]) by sj-core-3.cisco.com (8.12.10/8.12.6) with ESMTP id l4MJpQ0O007317; Tue, 22 May 2007 19:51:35 GMT
Received: from xfe-sjc-212.amer.cisco.com ([171.70.151.187]) by xbh-sjc-231.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Tue, 22 May 2007 12:51:32 -0700
Received: from [171.71.55.133] ([171.71.55.133]) by xfe-sjc-212.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Tue, 22 May 2007 12:51:32 -0700
In-Reply-To: <4652FC8D.3090600@piuha.net>
References: <8F47F550-6224-4AFF-8359-CBA98D3F2FAB@muada.com> <271CF87FD652F34DBF877CB0CB5D16FC054EA470@WIN-MSG-21.wingroup.windeploy.ntdev.microsoft.com> <62AFA8C7-FDD4-4FF2-B609-966081DDC0D1@cisco.com> <B79E458E-F18C-4617-B953-F311E5623E9A@cisco.com> <271CF87FD652F34DBF877CB0CB5D16FC054EA694@WIN-MSG-21.wingroup.windeploy.ntdev.microsoft.com> <A590D37E-7DEC-4695-998E-DA12A205F306@cisco.com> <271CF87FD652F34DBF877CB0CB5D16FC054EA741@WIN-MSG-21.wingroup.windeploy.ntdev.microsoft.com> <47DB1548-B91F-47A0-BF62-FACDA9E7706B@cisco.com> <20070518180916.GF69215@Space.Net> <3BD20378-6BEA-409D-A7E0-D170C0DF247D@cisco.com> <464E9D96.8070207@piuha.net> <4652E178.5080209@gmail.com> <4652FC8D.3090600@piuha.net>
Mime-Version: 1.0 (Apple Message framework v752.3)
Content-Type: text/plain; charset="US-ASCII"; delsp="yes"; format="flowed"
Message-Id: <6966E31B-F1D4-434B-9649-6C2B4B614F13@cisco.com>
Content-Transfer-Encoding: 7bit
From: Tony Li <tli@cisco.com>
Subject: Re: Manual network access logins (Was: Re: [RAM] The mapping problem: rendezvous points?)
Date: Tue, 22 May 2007 12:51:31 -0700
To: Jari Arkko <jari.arkko@piuha.net>
X-Mailer: Apple Mail (2.752.3)
X-OriginalArrivalTime: 22 May 2007 19:51:32.0063 (UTC) FILETIME=[9885D6F0:01C79CAA]
DKIM-Signature: v=0.5; a=rsa-sha256; q=dns/txt; l=840; t=1179863504; x=1180727504; c=relaxed/simple; s=sjdkim7002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=tli@cisco.com; z=From:=20Tony=20Li=20<tli@cisco.com> |Subject:=20Re=3A=20Manual=20network=20access=20logins=20(Was=3A=20Re=3A= 20[RAM]=20The=20mapping=20problem=3A=20rendezvous=20points?) |Sender:=20; bh=EbgIAU9wIGn+q7XoFcYT9K6FKqFD2m0FmsV/TQg7IsQ=; b=YhD8HusrL27fm01yHhAETE72pKZqeig2Dm7YvM4t/24XdnmvjLMQUMX1A+NDv9+RWg/xr/cs o14w7uwULMMXgNKoO90ufP47JIr1szQ6ZDuHN59/g/O8JVd2w+Y4YWML;
Authentication-Results: sj-dkim-7; header.From=tli@cisco.com; dkim=pass (sig from cisco.com/sjdkim7002 verified; );
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab
Cc: ram@iab.org, Gert Doering <gert@Space.Net>
X-BeenThere: ram@iab.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Routing and Addressing Mailing List <ram.iab.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ram>, <mailto:ram-request@iab.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/ram>
List-Post: <mailto:ram@iab.org>
List-Help: <mailto:ram-request@iab.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ram>, <mailto:ram-request@iab.org?subject=subscribe>
Errors-To: ram-bounces@iab.org

>> Are we really boiling that corner of the ocean here?
>
> No, we should not be. But if people have ideas
> about this corner of the ocean, we could talk
> about another effort. At the moment I'm not sure
> what more we can do technically, however. If
> there is something, contact me off the list and
> we can talk.


I'm not an expert in this area, but isn't this type of thing already  
addressed by 802.1x?

Even if not, it's not hard to see the we will want to have automated  
authentication mechanisms that allow us to change networks without  
manual intervention.  So while we might not be there yet, this is a  
AAA problem that someone should go off and solve.  The network  
architecture itself should still allow for these transitions to be as  
seamless as possible, including session migration.

Tony

_______________________________________________
RAM mailing list
RAM@iab.org
https://www1.ietf.org/mailman/listinfo/ram