Hello,
after the valuable comments received from Jim Schaad and Yoshihiro Ohba,
and further internal discussion, we have uploaded an updated version of
the RADIUS fragmentation draft.
The most relevant changes include:
* Fragmentation can only occur after authentication. Clients wanting
to send large amounts of data can signal this situation on the first
Access-Request, but the exchange will happen after authentication is
completed for security reasons.
* More-Data-Pending is now called Frag-Status, and its functionality
has been extended to cover other fragmentation signalling (including
the More-Data-Pending one).
* Access-Accept fragmentation is based on a series of Access-Accept
packets, not mixing different types.
* Security considerations and IANA considerations have been
significantly improved.
* The section regarding interaction with EAP has been removed, as it
does not make sense any more.
* Included discussion about allowed large packet size and its security
implications.
* Included discussion about unsupported packet types (i.e. accounting
and CoA) and the rationale behind that decision.
Regards,
Alejandro
-------- Mensaje original --------
Asunto: New Version Notification for
draft-perez-radext-radius-fragmentation-05.txt
Fecha: Fri, 08 Feb 2013 01:01:48 -0800
De: [email protected]
Para: [email protected]
CC: [email protected], [email protected], [email protected],
[email protected], [email protected]
A new version of I-D, draft-perez-radext-radius-fragmentation-05.txt
has been successfully submitted by Alejandro Perez-Mendez and posted to the
IETF repository.
Filename: draft-perez-radext-radius-fragmentation
Revision: 05
Title: Support of fragmentation of RADIUS packets
Creation date: 2013-02-08
WG ID: Individual Submission
Number of pages: 27
URL:
http://www.ietf.org/internet-drafts/draft-perez-radext-radius-fragmentation-05.txt
Status:
http://datatracker.ietf.org/doc/draft-perez-radext-radius-fragmentation
Htmlized:
http://tools.ietf.org/html/draft-perez-radext-radius-fragmentation-05
Diff:
http://www.ietf.org/rfcdiff?url2=draft-perez-radext-radius-fragmentation-05
Abstract:
This document describes a mechanism providing fragmentation support
of RADIUS packets that exceed the 4096 bytes limit.
The IETF Secretariat
_______________________________________________
abfab mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/abfab