On Wed, 2 Jul 2025 at 22:12, Michael Richardson <mcr+i...@sandelman.ca>
wrote:


> Alan and I had written draft-richardson-emu-eap-onboarding back in 2022,
> which was about defining a useful thing to do EAP-TLS *without* a client
> certificate.
> That used nob...@eap.arpa.
>
> Alan then decided that defining @eap.arpa first would be a good idea.
> And I think that document is now past WGLC, and so maybe it's time to
> resume
> work on emu-eap-onboarding.  I would be happy to update it based upon
> eap-arpa changes before the deadline.
> Does the WG need/want a presentation on it before going to a possible
> adoption call?
>

If there's time, I'd be interested to see your presentation.

In case a look at the existing related functionality is useful, here are
again links to wpa_supplicant repository that show commits of:

1. UNAUTH-TLS vendor specific EAP type - this method includes only server
authentication
https://w1.fi/cgit/hostap/commit/?id=065d2895b4693e8c923580dbfa31123297c8bb7d

2. HS 2.0R2: Add WFA server-only EAP-TLS peer method
I think this is the method that is referenced by
https://www.ietf.org/archive/id/draft-ietf-emu-eap-arpa-07.html#section-4.1-3
https://w1.fi/cgit/hostap/commit/?id=8e5fdfabf69a7692d1a0d04f00fa103e9ff72010

By again I mean that these were mentioned on the list some time ago and, as
far as I know, nothing new related has come up.

It looks to me your draft is focused on what happens just before and
immediately after when network connectivity has been achieved with, the
methods 1 or 2 above. I'd say my questions are:

- How does your draft relate to the two methods and implementations above?
Does it simply use them to get connected?
- If not related, does your draft define a new mutually unauthenticated
version of EAP-TLS?
- Do all these need to be synchronisation to avoid too many documents?

Looking forward to your presentation,
Heikki

-- 
Heikki Vatiainen
h...@radiatorsoftware.com
_______________________________________________
Emu mailing list -- emu@ietf.org
To unsubscribe send an email to emu-le...@ietf.org

Reply via email to