[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

EAP requestor for Initiator



Hi all,

In the ikev2 draft, explicitely describes EAP request initiated from
Responder. Is it legit to have EAP request initiated from Initiator?
Please see the below exchange. Is this against IKEv2 protocol?

Note: when I said EAP requestor, it means that the node sends the first
EAP packet.


  Initiator                          Responder
 -----------                        -----------
  HDR, SAi1, KEi, Ni         -->
                              <--    HDR, SAr1, KEr, Nr, [CERTREQ]

  HDR, SK {IDi, [CERTREQ,] [IDr,]
           SAi2, TSi, TSr}   -->
                              <--    HDR, SK {IDr, [CERT,] AUTH}
  HDR, SK {EAP, [AUTH]}      -->
                              <--    HDR, SK {EAP, [AUTH]}

  HDR, SK {EAP, [AUTH] }     -->
                              <--    HDR, SK {[AUTH], SAr2, TSi, TSr }

Thanks,

Tom Hu