: Question about NAI Realm based routing of RADIUS
"Dhaval Shah" <[email protected]> Wed, 14 Jun 2006 12:29:13 -0700
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
------=_NextPart_000_0076_01C68FAE.25058CC0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
Hi
I have a question about NAI
Realm based routing of AAA RADIUS
messages from say a 802.1x
authenticator to the Home AAA
server.
Consider the following example: (I
am using the notations from RFC
4282 (Network Access Identifier),
section 2.7)
Lets say autheticator received user
identity in EAP-Response packet as
NAI formed like
other2.example.net!home.example.net
[email protected]
This NAI will be converted by the
RADIUS client of the 802.1x
authenticator as
[email protected]
e.net
and forwarded to the IP address of
other2.example.net as a RADIUS
Access-Request.
My question is, RADIUS client
usually needs to share a "secret"
with AAA server, in the above
case where the client needs to send
the message through multiple
routing realms as coded
in the NAI, is it required that the
client MUST have a shared "secret"
with the first hop AAA
server/proxy towards the Home AAA
server? In the above case, does
802.1x authenticator
of other1.example.net needs to
share a "secret" with AAA server of
other2.example.net and
it MUST use that to prepare the
Message Authenticator? And
similarly, AAA server of
other2.example.net MUST share a
"secret" with home.example.net's
AAA server?
Also, what (if any) extensions must
be added to the RADIUS message
originating at the authenticator
to allow such realm based
forwarding of the packet to the
Home AAA server?
thanks
Dhaval
------=_NextPart_000_0076_01C68FAE.25058CC0
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2900.2873" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2>Hi</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2> I have a question about NAI Realm =
based routing=20
of AAA RADIUS messages from say a 802.1x</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial =
size=3D2>authenticator to the=20
Home AAA server.</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial =
size=3D2>Consider the=20
following example: (I am using the notations from RFC 4282 (Network =
Access=20
Identifier), section 2.7)</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>Lets =
say=20
autheticator received user identity in EAP-Response packet as NAI formed =
like</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2><A=20
href=3D"mailto:[email protected]=
t">[email protected]</A></FONT>=
</SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>This =
NAI will be=20
converted by the RADIUS client of the 802.1x authenticator=20
as</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2><A=20
href=3D"mailto:[email protected]">home.example.net=
[email protected]</A></FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>and =
forwarded to the=20
IP address of other2.example.net as a RADIUS =
Access-Request.</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>My =
question is,=20
RADIUS client usually needs to share a "secret" with AAA server, in the=20
above</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>case =
where the=20
client needs to send the message through multiple routing realms as=20
coded</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>in the =
NAI, is it=20
required that the client MUST have a shared "secret" with the first hop=20
AAA</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial =
size=3D2>server/proxy towards=20
the Home AAA server? In the above case, does 802.1x=20
authenticator</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>of=20
other1.example.net needs to share a "secret" with AAA server of=20
other2.example.net and</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>it =
MUST use that to=20
prepare the Message Authenticator? And similarly, AAA server=20
of</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial =
size=3D2>other2.example.net=20
MUST share a "secret" with home.example.net's AAA =
server?</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>Also, =
what (if any)=20
extensions must be added to the RADIUS message originating at the=20
authenticator</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial size=3D2>to =
allow such realm=20
based forwarding of the packet to the Home AAA =
server?</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2>thanks</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2>Dhaval</FONT></SPAN></DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV>
<DIV><SPAN class=3D890351719-14062006><FONT face=3DArial=20
size=3D2></FONT></SPAN> </DIV></BODY></HTML>
------=_NextPart_000_0076_01C68FAE.25058CC0--