(racoon2 36) Re: racoon2 + EAP Authentication (+EAP Method SIM/AKA)

"Dustin D. Trammell" <[email protected]> Tue, 06 Dec 2005 09:52:35 -0600
Newsgroups gmane.network.ipv6.kame.racoon
Organization Sipera Systems Inc.
Message-ID <1133884355.20474.393.camel@localhost>
--=-ZI7f/cJ/rg8nJ8XCx5Au
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Tue, 2005-12-06 at 23:36 +0900, Satoshi Inoue wrote:
> "Dustin D. Trammell" <[email protected]> wrote:
>=20
> > I am currently evaluating the possibility of integrating the EAP
> > implementation from Xsupplicant (or FreeRADIUS, or OpenDiameter) into
> > racoon2 as an auth method for IKEv2.  I noticed in the racoon2 code
> > there are various comments and the beginnings of functions to support
> > EAP.  Is anyone is actively working on adding EAP support to racoon2 or
> > should continue with my own efforts?
>=20
> Currently, no project member is working actively on adding EAP
> support. If it is possible for you to contribute the code, that
> will be great, and will definitely be appreciated. Have you had
> a thought about contributing the code to the racoon2 project?

If I am able to get it working and it's not too much of a hack-up, I
will most likely contribute my modifications back to the project.
Unfortunately my modifications are getting fairly messy so it may end up
being just a hack-up since I need to get this working for a very
specific application fairly quickly...

I'm currently trying to rework the EAP implementation from Xsupplicant
to work with racoon2, however Xsupplicant's EAP implementation was
designed to run over EAPOL and some of it's EAP state machine looks
fairly well integrated with it's EAPOL code so I'm not sure how well
ripping that out is going to work yet.  As I mentioned in my first
email, my other two apparent options are using EAP from FreeRADIUS or
OpenDiameter.

Of course I'm still in the learning phase so perhaps once I understand
Xsupplicant's EAP implementation and how the racoon2 internals work a
little better I may be able to code this functionality in properly, but
right now how racoon2's various functions interact is still a little
vague to me.  Do the project developers have any additional
documentation such as a function reference or a process flowchart?
Right now I'm slowly reading through the code and trying to make my own
but that it slow-going.  If that type of documentation already exists I
would greatly appreciate looking at it (:=20

--=20
Dustin D. Trammell
Vulnerability Researcher
Sipera Systems Inc. http://www.sipera.com

--=-ZI7f/cJ/rg8nJ8XCx5Au
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQBDlbPDiJrIfB1nTHwRAo24AJ9FgkZzcwqWWp1oebs87ZsPi0MA6gCeMb+w
cYjQw8yGIk+luB6F7LiIsdQ=
=FEYA
-----END PGP SIGNATURE-----

--=-ZI7f/cJ/rg8nJ8XCx5Au--