[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [HOKEY] WGLC: draft-ietf-hokey-preauth-ps-02



Hi Preetida,

Thank you for reviewing the draft.  I have a comment on your comment #2.

On Mon, Mar 31, 2008 at 08:48:06AM +0300, Preetida.Vinayakray-Jani at nokia.com wrote:
> >> 
> >> 2. In indirect pre-autnetication, it is asusmed that there will be
> >> pre-exisitng trust between SA and CA. To me this scenario is 
> >analogus to
> >> fast handover in MIP, with proxy-solicitation msg. However 
> >keeping MIP
> >> aside, even if MN receives IP level details of CA through SA, the
> >> performed pre-authentication can be partial as MN still needs to
> >> associate CA first before using IP level security. Any comments?   
> >
> >AD. The draft does not make any assumption regarding 
> >pre-established  SA 
> >between SA and CA, as SA (Serving Authenticator) acts like a proxy and 
> >forwards the packets to CA (Candidate Authenticator). MN does not 
> >directly communicate with CA, but SA does communicate with CA 
> >in case of 
> >indirect pre-authentication. So the role of CA and SA are little 
> >different than PAR and NAR that you have mentioned for FMIPv6.
> >
> >I do not understand quite well about the partial pre-authentication of 
> >MN. Could you please clarify it little more?
> >
> 
> [Preeti] Parital authentication -> In above scenrio, Preauthentication
> involves direct IP level communication between SA and CA, Although
> resulted pre-authentication is for MN, it does not include MN's layer 2
> authentication. Hence it is partial. If layer 2 authentication fails
> then success of layer 3 may not bring any value or underutilization of
> reserved resources. 

Direct pre-authentication and indirect pre-authentication are the same
in that both happen before MN performs L2 secure association to CA.
Context Binding, described in Section 5.2, will create binding between
link-layer independent context and link-layer specific context, so
that L2 secure association can succeed when L2 handover happens.

Yoshihiro Ohba

_______________________________________________
HOKEY mailing list
HOKEY at ietf.org
https://www.ietf.org/mailman/listinfo/hokey