[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [HOKEY] WGLC: draft-ietf-hokey-preauth-ps-02
Hi Preetida,
Thank you for reviewing the draft. I have a comment on your comment #2.
On Mon, Mar 31, 2008 at 08:48:06AM +0300, Preetida.Vinayakray-Jani at nokia.com wrote:
> >>
> >> 2. In indirect pre-autnetication, it is asusmed that there will be
> >> pre-exisitng trust between SA and CA. To me this scenario is
> >analogus to
> >> fast handover in MIP, with proxy-solicitation msg. However
> >keeping MIP
> >> aside, even if MN receives IP level details of CA through SA, the
> >> performed pre-authentication can be partial as MN still needs to
> >> associate CA first before using IP level security. Any comments?
> >
> >AD. The draft does not make any assumption regarding
> >pre-established SA
> >between SA and CA, as SA (Serving Authenticator) acts like a proxy and
> >forwards the packets to CA (Candidate Authenticator). MN does not
> >directly communicate with CA, but SA does communicate with CA
> >in case of
> >indirect pre-authentication. So the role of CA and SA are little
> >different than PAR and NAR that you have mentioned for FMIPv6.
> >
> >I do not understand quite well about the partial pre-authentication of
> >MN. Could you please clarify it little more?
> >
>
> [Preeti] Parital authentication -> In above scenrio, Preauthentication
> involves direct IP level communication between SA and CA, Although
> resulted pre-authentication is for MN, it does not include MN's layer 2
> authentication. Hence it is partial. If layer 2 authentication fails
> then success of layer 3 may not bring any value or underutilization of
> reserved resources.
Direct pre-authentication and indirect pre-authentication are the same
in that both happen before MN performs L2 secure association to CA.
Context Binding, described in Section 5.2, will create binding between
link-layer independent context and link-layer specific context, so
that L2 secure association can succeed when L2 handover happens.
Yoshihiro Ohba
_______________________________________________
HOKEY mailing list
HOKEY at ietf.org
https://www.ietf.org/mailman/listinfo/hokey