I added these issues to the issue list at http://www3.tools.ietf.org/wg/emu/trac/report/1
Joe > -----Original Message----- > From: Tschofenig,Hannes (NSN - DE/Germany - MiniMD) > [mailto:[EMAIL PROTECTED] > Sent: Thursday, September 20, 2007 1:51 AM > To: [email protected] > Subject: [Emu] Open Issues with EAP-GPSK > > > Hi all, > > Paul Rowe, Arnab Roy, Prof. Andre Scedrov and Prof. John C. > Mitchell did an analysis of EAP-GPSK and they essentially > found three issues: > > 1) Use of encryption algorithms before choice is confirmed > > This aspect can be covered in the security consideration > section of the upcoming draft version of EAP-GPSK: > http://www.tschofenig.com/svn/draft-clancy-emu-eap-gpsk/draft- > ietf-emu-e > ap-gpsk-07.txt > > 2) Mitigation of potential DOS attack against client > > This aspect is a bit more controversial and we would require > feedback from the group. I will post a separate mail on this subject. > > 3) Potential problem with the key derivation function > > This aspect also requires feedback from the group and a > separate mail will be posted to the list. > > Ciao > Hannes > > PS: Thanks to the group for doing the analysis and for > discussing the issues with us. > > > _______________________________________________ > Emu mailing list > [email protected] > https://www1.ietf.org/mailman/listinfo/emu > _______________________________________________ Emu mailing list [email protected] https://www1.ietf.org/mailman/listinfo/emu
