[Emu] Re: New issues with TEAP, and proposed document updates

2024-12-30 Thread Oleg Pekar
Hi, Few comments: >Change 1 >Clarify text on "TLS inside of TLS". This change has no impact on the >protocol or implementations, and is editorial. "The second use-case for EAP-TLS in Phase 2 is where both the user and machine use client certificates for authentication. Since TLS permits only one

[Emu] Re: New issues with TEAP, and proposed document updates

2024-12-30 Thread Alan DeKok
On Dec 30, 2024, at 12:44 PM, Oleg Pekar wrote: > "The second use-case for EAP-TLS in Phase 2 is where both the user and > machine use client certificates for authentication. Since TLS permits > only one client certificate to be presented, only one certificate can > be used in Phase 1." > > How a

[Emu] New issues with TEAP, and proposed document updates

2024-12-30 Thread Alan DeKok
Jouni Malinen and I have been having off-line discussions about TEAP implementations. Some analysis leads us to conclude that 7170bis needs some changes. The good news is that these changes simply document existing behavior. They address corner cases which were under-specified in earlier