Re: [Emu] RFC7170bis and lack of identities

2023-02-03 Thread Alexander Clouter
On Sat, 4 Feb 2023, at 01:40, Alan DeKok wrote: >> Should we state somewhere that the client can "effectively rollback the >> entire inner state machine" so Result TLV is not final for the whole session? >> >> Should the client be able to do this multiple times? > > I would say "no". I really

Re: [Emu] RFC7170bis and lack of identities

2023-02-03 Thread Alan DeKok
On Feb 3, 2023, at 6:56 AM, Alexander Clouter wrote: > Another chunk of greyness (at least to me) is the server has sent a Result > TLV (not intermediate) and then later after another method or chain of > methods it is expected to send it again. I would argue that Result TLV is final. The In

Re: [Emu] Secdir last call review of draft-ietf-emu-tls-eap-types-11

2023-02-03 Thread Alan DeKok
On Feb 3, 2023, at 8:19 PM, Melinda Shore via Datatracker wrote: > > Reviewer: Melinda Shore > Review result: Ready > > This document updates TLS-based EAP methods to use key derivation mechanisms > from TLS 1.3, along with other TLS 1.3-required updates. It's clearly written > and I believe c

[Emu] Secdir last call review of draft-ietf-emu-tls-eap-types-11

2023-02-03 Thread Melinda Shore via Datatracker
Reviewer: Melinda Shore Review result: Ready This document updates TLS-based EAP methods to use key derivation mechanisms from TLS 1.3, along with other TLS 1.3-required updates. It's clearly written and I believe could be implemented from. There are several very minor nits, which I actually don

Re: [Emu] RFC7170bis and lack of identities

2023-02-03 Thread Alexander Clouter
On Thu, 2 Feb 2023, at 19:16, Alan DeKok wrote: >> The documentation does not but I did see Appendix C.9 lets the client state >> what it wants to do: >> >> https://datatracker.ietf.org/doc/html/draft-ietf-emu-rfc7170bis-03#name-c9-peer-requests-inner-meth > > i.e. the client authenticates in p