Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-20 Thread Sam Hartman
I'm fine with this text. Either with eap-lower-layer as a MUST or the more complex version.

RE: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-20 Thread Black, David
, 2013 7:23 PM To: Black, David Cc: stefan.win...@restena.lu; General Area Review Team; ab...@ietf.org; ietf@ietf.org Subject: Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03 Thanks for the text, some revision to address On Jun 18, 2013, at 12:34 PM, Black, David david.bl

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-19 Thread Joseph Salowey (jsalowey)
...@ietf.orgmailto:ab...@ietf.org; ietf@ietf.orgmailto:ietf@ietf.org Subject: Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03 I think we could state this a bit better as something like: In environments where EAP is used for applications authentication and network access authentication all

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Sam Hartman
Black, == Black, David david.bl...@emc.com writes: Black, The next to last paragraph on p.3 begins with this sentence: Black,For these reasons, channel binding MUST be implemented by Black, peers, EAP servers and AAA servers in environments where EAP Black, authentication is

RE: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Black, David
Subject: Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03 Black, == Black, David david.bl...@emc.com writes: Black, The next to last paragraph on p.3 begins with this sentence: Black,For these reasons, channel binding MUST be implemented by Black, peers

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Joseph Salowey (jsalowey)
On Jun 18, 2013, at 7:18 AM, Sam Hartman hartm...@painless-security.com wrote: Black, == Black, David david.bl...@emc.com writes: Black, The next to last paragraph on p.3 begins with this sentence: Black,For these reasons, channel binding MUST be implemented by Black,

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Joseph Salowey (jsalowey)
I think we could state this a bit better as something like: In environments where EAP is used for applications authentication and network access authentication all EAP servers MUST understand channel bindings and require that application bindings MUST be present in application

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Sam Hartman
Joe, eap-lower-layer is not required for application authentication if there's some other attribute that's specific to the lower layer. For example Moonshot sends gss-acceptor-service-name but does not currently send eap-lower-layer, and doing that seems consistent with the requirements of the

Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Joseph Salowey (jsalowey)
On Jun 18, 2013, at 11:39 AM, Sam Hartman hartm...@painless-security.com wrote: Joe, eap-lower-layer is not required for application authentication if there's some other attribute that's specific to the lower layer. For example Moonshot sends gss-acceptor-service-name but does not currently

RE: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Black, David
Team; ab...@ietf.org; ietf@ietf.org Subject: Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03 On Jun 18, 2013, at 7:18 AM, Sam Hartman hartm...@painless-security.com wrote: Black, == Black, David david.bl...@emc.com writes: Black, The next to last paragraph on p.3

RE: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03

2013-06-18 Thread Black, David
Area Review Team; ab...@ietf.org; ietf@ietf.org Subject: Re: [abfab] Gen-ART review of draft-ietf-abfab-eapapplicability-03 I think we could state this a bit better as something like: In environments where EAP is used for applications authentication and network access authentication