So, is your concern with using only MSK crypto binding with an inner EAP authentication method used to authenticate an unauthenticated/poorly authenticated tunnel or is it more specific to the nea-pt-eap method?
For the first concern it may be sufficient to discuss the issue in the security considerations. If the concern is more about specifics of TLS-unique in nea-pt-eap not being adequate then we need to better understand what the concern is. I don't think the goal of the TLS-unique in nea-pt-eap is to provide server authentication, rather its to prevent the nea data from being used in a context different than it was generated. Thanks, Joe On Jun 6, 2012, at 12:09 PM, Sam Hartman wrote: > I don't believe that existing crypto binding is adequate for NEA's needs > as discussed in draft-hartman-emu-mutual-crypto-binding. > > Unfortunately, though, I'm not sure that tls-unique helps enough here. If > the outer method actually does provide server authentication as > deployed, then tls-unique is adequate. TLS-unique is preferable to > crypto-binding because it allows you to determine whether you're talking > about the right tunnel in the scope of the inner method--prior to doing > the NEA assessment--rather than in the scope of the outer method. (Also, > I'd assume this method does not generate a particularly useful key, so > crypto binding is not that helpful) > > However, if you're depending on something other than the outer method > for server authentication, then TLS-unique is not good enough. _______________________________________________ Emu mailing list [email protected] https://www.ietf.org/mailman/listinfo/emu
