Re: [Emu] EAP-TLS protected result indications

2021-02-03 Thread John Mattsson
. Adding this would however undoubtely delay the specification. Cheers, John From: Emu on behalf of Bernard Aboba Date: Wednesday, 3 February 2021 at 02:14 To: "j...@salowey.net" Cc: EMU WG Subject: Re: [Emu] EAP-TLS protected result indications The discussion largely happened in 80

Re: [Emu] EAP-TLS protected result indications

2021-02-02 Thread Bernard Aboba
The discussion largely happened in 802.11 since that was where the vulnerability vulnerability was discovered (by Bill Arbaugh at UMD). Documentation of the required signals was in RFC 4137, tests on the fixed implementations were done by UMD and subsequent analysis and security proofs were done by

Re: [Emu] EAP-TLS protected result indications

2021-02-02 Thread Joseph Salowey
On Tue, Feb 2, 2021 at 11:41 AM Bernard Aboba wrote: > Joe Salowey said: > > "[Joe] Based on RFC 5216 the server could fail the finished message or as > > section 2.1.3 shows it could send the finish and then it can send an Alert > and result in EAP-Failure. In this case it would be possible fo