I added these issues to the issue list at
http://www3.tools.ietf.org/wg/emu/trac/report/1

Joe 

> -----Original Message-----
> From: Tschofenig,Hannes (NSN - DE/Germany - MiniMD) 
> [mailto:[EMAIL PROTECTED] 
> Sent: Thursday, September 20, 2007 1:51 AM
> To: [email protected]
> Subject: [Emu] Open Issues with EAP-GPSK
> 
> 
> Hi all, 
>  
> Paul Rowe, Arnab Roy, Prof. Andre Scedrov and Prof. John C. 
> Mitchell did an analysis of EAP-GPSK and they essentially 
> found three issues:
> 
> 1) Use of encryption algorithms before choice is confirmed
> 
> This aspect can be covered in the security consideration 
> section of the upcoming draft version of EAP-GPSK:
> http://www.tschofenig.com/svn/draft-clancy-emu-eap-gpsk/draft-
> ietf-emu-e
> ap-gpsk-07.txt
> 
> 2) Mitigation of potential DOS attack against client 
> 
> This aspect is a bit more controversial and we would require 
> feedback from the group. I will post a separate mail on this subject. 
> 
> 3) Potential problem with the key derivation function
> 
> This aspect also requires feedback from the group and a 
> separate mail will be posted to the list. 
> 
> Ciao
> Hannes
> 
> PS: Thanks to the group for doing the analysis and for 
> discussing the issues with us. 
> 
> 
> _______________________________________________
> Emu mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/emu
> 


_______________________________________________
Emu mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/emu

Reply via email to