[Emu] I-D Action: draft-ietf-emu-aka-pfs-06.txt

2022-03-07 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the EAP Method Update WG of the IETF. Title : Forward Secrecy for the Extensible Authentication Protocol Method for Authentication and Key Agreement (EAP-AKA' FS)

Re: [Emu] Working Group Last Call for TLS-based EAP types and TLS 1.3

2022-03-07 Thread Hannes Tschofenig
Maybe it is a terminology issue but TLS at least requires server-authentication. From: Emu On Behalf Of Heikki Vatiainen Sent: Monday, March 7, 2022 2:41 PM To: Alan DeKok Cc: EMU WG Subject: Re: [Emu] Working Group Last Call for TLS-based EAP types and TLS 1.3 On Fri, 4 Mar 2022 at 21:44,

Re: [Emu] Working Group Last Call for TLS-based EAP types and TLS 1.3

2022-03-07 Thread Alan DeKok
On Mar 7, 2022, at 8:40 AM, Heikki Vatiainen wrote: > I suggest for this document that we just forbid the case of using only a > client certificate with TTLS. > > No objection from me - and it now appears to be in draft version -05. While > there may have been client software that supported

Re: [Emu] Working Group Last Call for TLS-based EAP types and TLS 1.3

2022-03-07 Thread Heikki Vatiainen
On Fri, 4 Mar 2022 at 21:44, Alan DeKok wrote: > I would argue that EAP-TTLS with only a client certificate doesn't make > sense. I'm not sure why it's in RFC 5281. If you want to only use a > client certificate, you should just use EAP-TLS. > > I suggest for this document that we just

[Emu] New drafts EAP-NOOB-Observations and EAP-UTE

2022-03-07 Thread Jan-Frederik Rieckers
Hi to all, For a Masters project at the University of Bremen and in my capacity as one of the national roaming operators for eduroam in Germany at the German National Research and Education Network I am currently looking into EAP-NOOB. While reading the then draft, now RFC, for EAP-NOOB I