Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-06-08 Thread Mohit Sethi M
d these since they are still in early phases of development. However, I have now added a section titled "New Certificate Types and Compression Algorithms". Hope this is sufficient. > > Ciao > Hannes > > -Original Message- > From: Mohit Sethi M > Sent: Saturday,

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-06-08 Thread Hannes Tschofenig
ogress. Ciao Hannes -Original Message- From: Mohit Sethi M Sent: Saturday, May 9, 2020 10:49 AM To: Hannes Tschofenig ; Michael Richardson ; emu@ietf.org Subject: Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt Hi Hannes, I have submitted a new version

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-05-09 Thread Mohit Sethi M
Hi Hannes, I have submitted a new version of the draft which I believe addresses your concerns. Here is a diff for your convenience: https://www.ietf.org/rfcdiff?url2=draft-ietf-emu-eaptlscert-03 While Alan and Jouni have already provided excellent answers to most of your comments, in-line

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-28 Thread Hannes Tschofenig
Thanks, Jouni. That's a good clarification. -Original Message- From: Jouni Malinen Sent: Saturday, March 28, 2020 9:26 AM To: Alan DeKok Cc: Hannes Tschofenig ; emu@ietf.org Subject: Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt On Tue, Mar 24, 2020

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-28 Thread Jouni Malinen
On Tue, Mar 24, 2020 at 10:08:06AM -0400, Alan DeKok wrote: > On Mar 24, 2020, at 4:00 AM, Hannes Tschofenig > wrote: > >> For example, many EAP authenticator (access point) > >> implementations will drop an EAP session if it has not finished after > >> 40 - 50 round-trips. > > > > Is there a

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-25 Thread Alan DeKok
On Mar 25, 2020, at 3:30 AM, Hannes Tschofenig wrote: > Thanks a lot for your comments. I guess you understand that I am always a bit > nervous when the results of non-public conversations dictate the problem > space. I have seen it often enough that people have made their measurements >

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-25 Thread Hannes Tschofenig
My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt On Mar 24, 2020, at 4:00 AM, Hannes Tschofenig wrote: > Having seen this statement from Michael I have reviewed the document. Two > generic observations about the draft: > > 1) Many statements are made about deploym

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Alan DeKok
On Mar 24, 2020, at 4:00 AM, Hannes Tschofenig wrote: > Having seen this statement from Michael I have reviewed the document. Two > generic observations about the draft: > > 1) Many statements are made about deployments and no references are provided. > To improve quality of the write-up I

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Eliot Lear
> On 24 Mar 2020, at 10:30, Hannes Tschofenig wrote: > > Hi Eliot, > > I consider the enterprise and the university case as a roaming model. From an > EAP method point of view there is IMHO little difference between the roaming > and the non-roaming case: the EAP exchange always runs

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Hannes Tschofenig
rdson mailto:mcr+i...@sandelman.ca>>; emu@ietf.org<mailto:emu@ietf.org> Subject: Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt Good morning Hannes Also, from deployment experience, EAP peers typically have longer certificate chains than servers. I would l

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Eliot Lear
> certificates/certificate chains occur would shine light on this aspect. > > Ciao > Hannes > > From: Eliot Lear > Sent: Tuesday, March 24, 2020 10:02 AM > To: Hannes Tschofenig > Cc: Michael Richardson ; emu@ietf.org > Subject: Re: [Emu] My review ... was

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Hannes Tschofenig
: Michael Richardson ; emu@ietf.org Subject: Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt Good morning Hannes Also, from deployment experience, EAP peers typically have longer certificate chains than servers. I would like a reference to be included here

Re: [Emu] My review ... was RE: I-D Action: draft-ietf-emu-eaptlscert-02.txt

2020-03-24 Thread Eliot Lear
Good morning Hannes > > >> Also, >> from deployment experience, EAP peers typically have longer >> certificate chains than servers. > > I would like a reference to be included here. Theoretically, it makes no > sense to > have a certificate chain for an EAP peer to have a longer certificate