Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt

Bernard Aboba <[email protected]> Thu, 29 May 2003 10:06:17 -0700 (PDT)
Newsgroups gmane.ietf.ppvpn
Message-ID <[email protected]>
> as i said in above, in most vpn implementations today, the ces doen't
> identify them selves at all.  in that respect my proposal in a big
> improvement, because if the ce is 802.1x capable, it can identify
> itself.

In RADIUS "Call Check" or "Authorize Only" exchanges, the PE need not have
an identification exchange with the CE.  However, the PE still needs to
identify the CE somehow in the RADIUS Access-Request.  So even if there is
no identity exchange, you still need to put something into the User-Name
attribute.  In a "Call Check" service that could be an L2 address (phone
# or MAC address) or it could be a user name.  Ideally it's the identity
that you determine somehow by the alternative auth mechanism (e.g. OSPF
MD5).