So, is your concern with using only MSK crypto binding with an  inner EAP 
authentication method used to authenticate an unauthenticated/poorly 
authenticated tunnel or is it more specific to the nea-pt-eap method? 

For the first concern it may be sufficient to discuss the issue in the security 
considerations.

If the concern is more about specifics of TLS-unique in nea-pt-eap not being 
adequate then we need to better understand what the concern is.  I don't think 
the goal of the TLS-unique in nea-pt-eap is to provide server authentication, 
rather its to prevent the nea data from being used in a context different than 
it was generated. 

Thanks,

Joe
On Jun 6, 2012, at 12:09 PM, Sam Hartman wrote:

> I don't believe that existing crypto binding is adequate for NEA's needs
> as discussed in draft-hartman-emu-mutual-crypto-binding.
> 
> Unfortunately, though, I'm not sure that tls-unique helps enough  here. If
> the outer method actually does provide server authentication as
> deployed, then tls-unique is adequate.  TLS-unique is preferable to
> crypto-binding because it allows you to determine whether you're talking
> about the right tunnel in the scope of the inner method--prior to doing
> the NEA assessment--rather than in the scope of the outer method. (Also,
> I'd assume this method does not generate a particularly useful key, so
> crypto binding is not that helpful)
> 
> However, if you're depending on something other than the outer method
> for server authentication, then TLS-unique is not good enough.

_______________________________________________
Emu mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/emu

Reply via email to