Re: [Int-area] DCHP-based authentication for DSL?

Alan DeKok <aland@nitros9.org> Thu, 25 October 2007 14:42 UTC

Return-path: <int-area-bounces@lists.ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1Il3uQ-0004ya-PU; Thu, 25 Oct 2007 10:42:06 -0400
Received: from int-area by megatron.ietf.org with local (Exim 4.43) id 1Il3uM-0004pE-Pf for int-area-confirm+ok@megatron.ietf.org; Thu, 25 Oct 2007 10:42:02 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1Il3uM-0004nX-Fs for int-area@lists.ietf.org; Thu, 25 Oct 2007 10:42:02 -0400
Received: from www.deployingradius.com ([216.240.42.17] helo=deployingradius.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Il3uE-0005ym-1C for int-area@lists.ietf.org; Thu, 25 Oct 2007 10:42:00 -0400
Received: from [10.0.1.38] (alexander.quiconnect.net [213.30.156.62]) by deployingradius.com (Postfix) with ESMTP id 594C2A704E; Thu, 25 Oct 2007 07:41:36 -0700 (PDT)
Message-ID: <4720AB16.6030804@nitros9.org>
Date: Thu, 25 Oct 2007 16:41:26 +0200
From: Alan DeKok <aland@nitros9.org>
User-Agent: Thunderbird 2.0.0.6 (X11/20071022)
MIME-Version: 1.0
To: Yoshihiro Ohba <yohba@tari.toshiba.com>
Subject: Re: [Int-area] DCHP-based authentication for DSL?
References: <005501c81555$6f49f360$ba3dfea9@ad.redback.com> <471F0F26.4070006@uninett.no> <471FACDD.3000707@cisco.com> <C087AF58-A3DF-40CC-9AB2-BE30E3657A00@cisco.com> <471FB475.3020409@cisco.com> <472046D9.5030903@nitros9.org> <20071025142921.GA13035@steelhead.localdomain>
In-Reply-To: <20071025142921.GA13035@steelhead.localdomain>
Content-Type: text/plain; charset="ISO-2022-JP"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab
Cc: Internet Area <int-area@lists.ietf.org>
X-BeenThere: int-area@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF Internet Area Mailing List <int-area.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/int-area>, <mailto:int-area-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/int-area>
List-Post: <mailto:int-area@lists.ietf.org>
List-Help: <mailto:int-area-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/int-area>, <mailto:int-area-request@lists.ietf.org?subject=subscribe>
Errors-To: int-area-bounces@lists.ietf.org

Yoshihiro Ohba wrote:
> DHCP MTU can still be an issue.
> 
> - EAP minimum MTU is 1020 octets.
> 
> - Some EAP methods (e.g., EAP-AKA) may not work with a lower layer
> where the MTU is less than EAP minimum MTU.

  That is likely, yes.

> It seems that your tests are based on an EAP method that supports
> fragmentation?

  Yes.  Some TLS-based methods (EAP-TLS, EAP-TTLS, and PEAP) appear to
be fine with small fragments.

  Don't take this test for more than what it is: a quick check of common
implementations.  It should not be construed as being definitive, or of
being standards compliant, or of working outside of a controlled test
environment.

  Alan DeKok.


_______________________________________________
Int-area mailing list
Int-area@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/int-area