Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt

Juha Heinanen <[email protected]> Fri, 23 May 2003 15:37:18 +0300
Newsgroups gmane.ietf.ppvpn
Message-ID <[email protected]>
Bernard Aboba writes:

 > Re-authentication can be accomplished by sending a Session-Time attribute
 > with Termination-Action=1.  However, there is also work underway (for
 > prepaid) to support re-authorization via the "Authorize Only" Service-Type
 > supported in draft-chiba.

yes, that way the pe would know when it needs to re-authenticate its
sites.

 > Not sure why using Interim Accounting would improve scalability as
 > compared with re-authorization.

as it is currently written, the pe is not required to authenticate all
its sites, but just to send any message to the radius server at least
every N minutes.  i proposed to use an accounting message for that
purpose, but it could as well be re-authentication message.

 > With this many sites you will definitely need to require some improvements
 > in RADIUS client retransmission behavior.  I've seen situations
 > with 3K+ RADIUS clients where the network could not come up again after a
 > power failure, due to overload on the RADIUS server.  Exponential backoff
 > + jittering would have helped, and we'll be putting together a document to
 > provide guidelines on how RADIUS client should behave.

the text mentions that pes should use exponential backoff. i guess that
it is standard practice in any protocol.

 > You can use draft-chiba to send a CoA-Request with Service-Type="Authorize
 > Only" in order to make this happen.

yes, perhaps so.  however, i would not like to make mandatory anything
that is beyond current standards.  optional recommendations based on
drafts are ok.

so where are we now?  are people happy if i make another version of the
draft, where the pes always re-authenticate all their sites every N
minutes and accounting keepalives are not used?  if so i can do it and
publish the new version as wg document.

-- juha