Hi Michael, That you very much for this review.
The new draft, http://tools.ietf.org/html/draft-urien-eap-smartcard-21 has been updated with the corrected value 1: Corrected In test #2 (Wrong SQN) you're calculating MAC-S with a non-zero AMF giving 7CD924E739F12369. According to 3GPP TS 33.102 AMF is set to zeros when calculating AUTS. When doing that I get 0010C1DA38A75A31 instead. 2: Corrected >>In test #6 (Reauth, Good Counter) the counter value is 0000, whereas RFC4187 specifies that the minimum counter value of the first packet should be 0001. Also, you use the 64-byte MSK value generated in test #1 instead of MK, whereas RFC4187 specifies XKEY'=SHA1(Identity|counter|NONCE_S|MK). This obviously gives a quite different result than what you get. 3:To be Corrected In the "Get MSK" commands in test #1 and test #6 the first 32 bytes of MSK are switched with the last 32 bytes of MSK. I don't see anything in your document stating that this should be the behaviour. The order is switched on supllicant side. To be documented 4: Corrected In test #6 and test #7 the MAC is not calculated over (EAP-packet | Nounce-S), as specified in RFC4187. Best Regards Pascal 2011/6/7 Michael Thomsen <[email protected]> > Hi Pascal, > > sorry, I don't quite understand what you mean by "former EAP-AKA version", > but I've stumpled upon a few things I don't quite understand: > > 1: > -- > In test #2 (Wrong SQN) you're calculating MAC-S with a non-zero AMF giving > 7CD924E739F12369. According to 3GPP TS 33.102 AMF is set to zeros when > calculating AUTS. When doing that I get 0010C1DA38A75A31 instead. > > According to RFC4187 AT_AUTS should include "the AKA AUTS parameter, 112 > bits" I don't see anything about the AMF field not being zeroed, as it is > per usual. > > 2: > -- > In test #6 (Reauth, Good Counter) the counter value is 0000, whereas > RFC4187 specifies that the minimum counter value of the first packet should > be 0001. Also, you use the 64-byte MSK value generated in test #1 instead of > MK, whereas RFC4187 specifies XKEY'=SHA1(Identity|counter|NONCE_S|MK). This > obviously gives a quite different result than what you get. > > 3: > -- > In the "Get MSK" commands in test #1 and test #6 the first 32 bytes of MSK > are switched with the last 32 bytes of MSK. I don't see anything in your > document stating that this should be the behaviour. > > 4: > -- > In test #6 and test #7 the MAC is not calculated over (EAP-packet | > Nounce-S), as specified in RFC4187. > > Kind regards, > Michael Thomsen > _______________________________________________ > Emu mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/emu >
_______________________________________________ Emu mailing list [email protected] https://www.ietf.org/mailman/listinfo/emu
