Re: FW: New Version Notification for draft-brzozowski-dhcp-eap-analysis-00
Alper Yegin <alper.yegin <at> yegin.org>
2009-07-03 08:21:18 GMT
I was really wondering about the thoughts of the authors. Since they did the
analysis, they must have considered these points (which were already raised
on the mailing list).
> > - The role of NAS with respect to DHCP is unclear. For some part it
> is
> > acting as a DHCP relay, for others as a DHCP server (as it
> > terminates DHCP
> > messages and generates DHCP messages -- for EAP). Is the NAS playing
> > two
> > distinct DHCP roles within the same DHCP session? How well does that
> > fit
> > DHCP?
>
> Yes, in Broadband the NAS can be a relay or a server at the operators
> choice.
At the same time for the same DHCP session? I don't think so. There is no
way (barring serious hacks) for a DHCP session be executed between one DHCP
client and multiple DHCP servers. [NAS acting as a relay for some DHCP
client for the duration of a DHCP session, and as a server for other clients
for the duration of a DHCP session is OK -- but that's not same as what is
in your I-D]
> > - NAS (acting as DHCP relay) is inserting DHCP options towards the
> > DHCP
> > client. I'm not aware of DHCP relays inserting options in that
> > direction. To
> > say the least, that breaks the end-to-end security, such as the one
> > using
(Continue reading)