Re: call for discussion on draft-heinanen-radius-pe-discovery-03.txt
Bernard Aboba <[email protected]> Thu, 29 May 2003 10:06:17 -0700 (PDT)
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <[email protected]> |
> as i said in above, in most vpn implementations today, the ces doen't > identify them selves at all. in that respect my proposal in a big > improvement, because if the ce is 802.1x capable, it can identify > itself. In RADIUS "Call Check" or "Authorize Only" exchanges, the PE need not have an identification exchange with the CE. However, the PE still needs to identify the CE somehow in the RADIUS Access-Request. So even if there is no identity exchange, you still need to put something into the User-Name attribute. In a "Call Check" service that could be an L2 address (phone # or MAC address) or it could be a user name. Ideally it's the identity that you determine somehow by the alternative auth mechanism (e.g. OSPF MD5).