We noticed a situation where our AAA server was generating a channel
binding response that was rejected by our supplicant code.

We looked into things and determined that the server was generating a
single octet failure response (code 3) and was including no attributes.

After re-reading section 5.3, we believe this is unambiguously permitted
and is correct behavior in the situation where we send it.
However, it was kind of non-intuitive to get a response back with no
information in it.

I don't think an erata is required, but I'd appreciate others looking at
the spec to confirm our reading.

Thanks,

--Sam
_______________________________________________
Emu mailing list
Emu@ietf.org
https://www.ietf.org/mailman/listinfo/emu

Reply via email to