IETF-84 EMU TEAP Updates Nancy Joseph Salowey Hao Zhou

Slides:



Advertisements
Similar presentations
1 IETF KEYPROV WG Protocol Basis and Characteristics IEEE P April 11, 2007 Andrea Doherty.
Advertisements

EAP Scenarios and 802.1af Joseph Salowey 1/12/2006.
Dynamic Symmetric Key Provisioning Protocol (DSKPP)
EAP Channel Bindings Charles Clancy Katrin Hoeper IETF 76 Hiroshima, Japan November 08-13, 2009.
IETF OAuth Proof-of-Possession
Lionel Morand DIME WG IETF 79 Diameter Design Guidelines Thursday, November 11, 2010 Lionel Morand.
1 IETF OAuth Proof-of-Possession Hannes Tschofenig.
EAP-TTLS Status draft-funk-eap-ttls-v0-00.txt draft-funk-eap-ttls-v1-00.txt draft-funk-tls-inner-application-extension-01.txt Paul Funk Funk Software.
Home Network Models Vijay Devarapalli draft-ietf-nemo-home-network-models-02 NEMO WG, IETF 62.
NEA Working Group IETF meeting Nov 17, 2011 IETF 82 - NEA Meeting1.
EAP Mutual Cryptographic Binding draft-ietf-karp-ops-model-03 draft-ietf-karp-ops-model-03 S. Hartman M. Wasserman D. Zhang.
SIP working group status Keith Drage, Dean Willis.
Eugene Chang EMU WG, IETF 70
Dynamic Symmetric Key Provisioning Protocol (DSKPP) Mingliang Pei Salah Machani IETF68 KeyProv WG Prague.
EAP WG EAP Key Management Framework Draft-ietf-eap-keying-03.txt Bernard Aboba Microsoft.
Yang Shi, Chris Elliott, Yong Zhang IETF 73 rd 18 Nov 2008, Minneapolis CAPWAP WG MIB Drafts Report.
Mtrace Version 2: Traceroute Facility for IP Multicast draft-ietf-mboned-mtrace-v2-07 Hitoshi Asaeda Tatsuya Jinmei Bill Fenner Steve Casner 78 th IETF,
1 /10 Pascal URIEN, IETF 66 h, Wednesday July 12 th,Montreal, Canada draft-urien-badra-eap-tls-identity-protection-00.txt
July 27, 2009IETF NEA Meeting1 NEA Working Group IETF 75 Co-chairs: Steve Hanna
Doc.: IEEE /1572r0 Submission December 2004 Harkins and AbobaSlide 1 PEKM (Post-EAP Key Management Protocol) Dan Harkins, Trapeze Networks
Cullen Jennings Certificate Directory for SIP.
Session Peering Protocol over SOAP I-D ( draft-ietf-drinks-spp-over-soap-01) draft-ietf-drinks-spp-over-soap-01 0 Presenter: Vikas Bhatia (On behalf of.
Maryland Information Systems Security Lab D EPARTMENT OF C OMPUTER S CIENCE EAP Password Authenticated eXchange (PAX) T. Charles Clancy William A. Arbaugh.
1 Diameter SIP application draft-ietf-aaa-diameter-sip-app-03.txt 60 th IETF meeting August 3 rd, 2004 Status.
PAWS: Security Considerations Yizhuang WU, Yang CUI PAWS WG
All Rights Reserved © Alcatel-Lucent 2007, ##### 1 | Presentation Title | January 2007 UMB Security Evolution Proposal Abstract: This contribution proposes.
Mar 22, 2010IETF NEA Meeting1 NEA Working Group (oauth is in Redondo!) IETF 77 Mar 22, Co-chairs:
BPI+ MIB Update IETF IPCDN WG 12/13/2000 Stuart Green - Nortel Networks / Arris Interactive Kaz Ozawa - Toshiba / CableLabs.
EAP-POTP Magnus Nyström, RSA Security 23 May 2005.
Node Information Queries July 2002 Yokohama IETF Bob Hinden / Nokia.
November 2005IETF 64, Vancouver, Canada1 EAP-POTP The Protected One-Time Password EAP Method Magnus Nystrom, David Mitton RSA Security, Inc.
March 2006 CAPWAP Protocol Specification Update March 2006
OSPF WG – IETF 67 OSPF WG Document Status or “You can bring a Horse to Water …” Rohit Dube/Consultant Acee Lindem/Cisco Systems.
EAP-FAST Version 2 draft-zhou-emu-eap-fastv2-00.txt Hao Zhou Nancy Cam-Winget Joseph Salowey Stephen Hanna March 2011.
EAP Keying Framework Draft-aboba-pppext-key-problem-06.txt EAP WG IETF 56 San Francisco, CA Bernard Aboba.
March 17, 2003 IETF #56, SAN FRANCISCO1 Compound Authentication Binding Problem (EAP Binding Draft) Jose Puthenkulam Intel Corporation (
Abierman-netconf-mar07 1 NETCONF WG 68 th IETF Prague, CZ March 19, 2007.
Overview of draft–16 for MIPv6 MIPv6 Design Team March 19 th, 2002.
Emu wg, IETF 70 Steve Hanna, EAP-TTLS draft-funk-eap-ttls-v0-02.txt draft-hanna-eap-ttls-agility-00.txt emu wg, IETF 70 Steve Hanna,
ISMS IETF72 David Harrington. Status IETF72 Transport Subsystem for the Simple Network Management Protocol (SNMP) –IETF69: draft-ietf-isms-tmsm-09.txt.
Channel Binding Support for EAP Methods Charles Clancy, Katrin Hoeper.
TLS Renegotiation Vulnerability IETF-76 Joe Salowey Eric Rescorla
RFC 2716bis Wednesday, July 12, 2006 Draft-simon-emu-rfc2716bis-02.txt Dan Simon Bernard Aboba IETF 66, Montreal, Canada.
NEA Working Group IETF meeting July 27, 2011 Jul 27, 2011IETF 81 - NEA Meeting1.
NEA Working Group IETF 72 Co-chairs: Steve Hanna Susan
RPKI Certificate Policy Status Update Stephen Kent.
IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: IETF Liaison Report Date Submitted: September 16, 2010 Presented at IEEE session.
August 2001 Slide 1 Extensions to TLS Simon Blake-Wilson Certicom David Hopwood Independent Consultant Jan Mikkelsen Transactionware Magnus Nystrom RSA.
Transport Layer Security (TLS) Extensions: Extension Definitions draft-ietf-tls-rfc4366-bis-00.
1 EAP-MAKE2: EAP method for Mutual Authentication and Key Establishment, v2 EMU BoF Michaela Vanderveen IETF 64 November 2005.
1 Extensible Authentication Protocol (EAP) Working Group IETF-57.
IETF68 DIME WG Diameter Applications Design Guidelines Document (draft-fajardo-dime-app-design-guide-00.txt)
SCVP-28 Tim Polk November 8, Current Status Draft -27 was submitted in June ‘06 –AD requested a revised ID 8/11 –No related discussion on list –Editors.
RADEXT WG RADIUS Attributes for WLAN Draft-aboba-radext-wlan-00.txt
PANA Discussion and Open Issues (draft-ietf-pana-pana-01.txt)
Jari Arkko, Henry Haverinen, Joseph Salowey (presented by Pasi Eronen)
for IP Mobility Protocols
ERP extension for EAP Early-authentication Protocol (EEP)
IETF-70 EAP Method Update (EMU)
The Tunneled Extensible Authentication Method (TEAM)
Charles Clancy Katrin Hoeper IETF 73 Minneapolis, USA 17 November 2008
IEEE IETF Liaison Report
STIR WG IETF-100 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-01) November, 2017 Ray P. Singh, Martin Dolly, Subir Das,
STIR WG IETF-99 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-00) July, 2017 Ray P. Singh, Martin Dolly, Subir Das, and An.
draft-ietf-p2psip-base-03
IEEE IETF Liaison Report
IEEE MEDIA INDEPENDENT HANDOVER DCN:
(draft-josefsson-pppext-eap-tls-eap-06.txt)
PANA enabling IPsec based Access control
Presentation transcript:

IETF-84 EMU TEAP Updates Nancy Joseph Salowey Hao Zhou Steve Hanna July 2012EMU WG1

draft-ietf-emu-eap-tunnel-method- 03 New version (03) submitted in June Several comments received on -02 All tickets have been resolved July 2012EMU WG 2

Changes from -02 SectionUpdates 3.3.3Clarified protected termination and use of crypto-binding TLV 3.5Changed Session ID to use tls-unique and added reference to RFC5247.RFC Added the use of tls-unique to the certificate enrollment request Modified Request-Action TLV to include Status code and optional TLVs. 3.4Clarified that all authenticated Peer-Ids need to be exported. 5.1Changed TLS Keying Material Exporter label to "teap seesion key seed". 5.2Changed Intermediate Compound Key Derivation from MSK to EMSK generated by inner method. 6Added missing IANA considerations. 7.3Added more security considerations for separation of Phase 1 and Phase 2 servers. Appendix CUpdated examples with Request-Action TLV, channel binding, and sending certificate after TLS renegotiation. July 2012EMU WG 3

EMSK in Crypto-Binding If Method generates an EMSK then it is used in the binding If method does not generate an EMSK then MSK is used If method does not generate MSK or EMSK then key is set to 0 (no key to bind to) July 2012EMU WG 4

Certificate Enrollment Use TLS-unique for binding Should we align with EST? – July 2012EMU WG 5

Next Steps Call for review and WGLC after IETF-84 July 2012EMU WG 6

Questions? July 2012EMU WG7