Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt
Juha Heinanen <[email protected]> Fri, 23 May 2003 15:37:18 +0300
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <[email protected]> |
Bernard Aboba writes: > Re-authentication can be accomplished by sending a Session-Time attribute > with Termination-Action=1. However, there is also work underway (for > prepaid) to support re-authorization via the "Authorize Only" Service-Type > supported in draft-chiba. yes, that way the pe would know when it needs to re-authenticate its sites. > Not sure why using Interim Accounting would improve scalability as > compared with re-authorization. as it is currently written, the pe is not required to authenticate all its sites, but just to send any message to the radius server at least every N minutes. i proposed to use an accounting message for that purpose, but it could as well be re-authentication message. > With this many sites you will definitely need to require some improvements > in RADIUS client retransmission behavior. I've seen situations > with 3K+ RADIUS clients where the network could not come up again after a > power failure, due to overload on the RADIUS server. Exponential backoff > + jittering would have helped, and we'll be putting together a document to > provide guidelines on how RADIUS client should behave. the text mentions that pes should use exponential backoff. i guess that it is standard practice in any protocol. > You can use draft-chiba to send a CoA-Request with Service-Type="Authorize > Only" in order to make this happen. yes, perhaps so. however, i would not like to make mandatory anything that is beyond current standards. optional recommendations based on drafts are ok. so where are we now? are people happy if i make another version of the draft, where the pes always re-authenticate all their sites every N minutes and accounting keepalives are not used? if so i can do it and publish the new version as wg document. -- juha