<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: RSA keypair, Radius and StokeOS for IKEv2-EAP Authentication</title>
	<atom:link href="http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html</link>
	<description>&#34;You know my methods, Watson...&#34;</description>
	<lastBuildDate>Thu, 09 Feb 2012 13:55:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jimmy's Blog</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-10121</link>
		<dc:creator>Jimmy's Blog</dc:creator>
		<pubDate>Thu, 31 Mar 2011 21:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-10121</guid>
		<description>&lt;strong&gt;Linky, linky, blogs we likey...&lt;/strong&gt;

[...]while the sites we link to below are completely unrelated to ours, we think they are worth a read, so have a look[...]...</description>
		<content:encoded><![CDATA[<p><strong>Linky, linky, blogs we likey&#8230;</strong></p>
<p>[...]while the sites we link to below are completely unrelated to ours, we think they are worth a read, so have a look[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unlock iPhone4</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-9949</link>
		<dc:creator>Unlock iPhone4</dc:creator>
		<pubDate>Thu, 17 Mar 2011 12:21:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-9949</guid>
		<description>Hi! I know this is kinda off topic but I&#039;d figured I&#039;d ask. Would you be interested in exchanging links or maybe guest authoring a blog post or vice-versa? My blog goes over a lot of the same subjects as yours and I believe we could greatly benefit from each other. If you happen to be interested feel free to shoot me an email. I look forward to hearing from you! Awesome blog by the way!</description>
		<content:encoded><![CDATA[<p>Hi! I know this is kinda off topic but I&#8217;d figured I&#8217;d ask. Would you be interested in exchanging links or maybe guest authoring a blog post or vice-versa? My blog goes over a lot of the same subjects as yours and I believe we could greatly benefit from each other. If you happen to be interested feel free to shoot me an email. I look forward to hearing from you! Awesome blog by the way!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cristina_crow</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-4898</link>
		<dc:creator>cristina_crow</dc:creator>
		<pubDate>Fri, 09 Jul 2010 15:24:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-4898</guid>
		<description>New StokeOS (4.6B1), new commands to bind the certs:
certificate device-certificate new name SSX ca-certificate CA.cer format pem signed-certificate ssx-185.pem format pem private-key ssx-185.key</description>
		<content:encoded><![CDATA[<p>New StokeOS (4.6B1), new commands to bind the certs:<br />
certificate device-certificate new name SSX ca-certificate CA.cer format pem signed-certificate ssx-185.pem format pem private-key ssx-185.key</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas Steffen</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-3693</link>
		<dc:creator>Andreas Steffen</dc:creator>
		<pubDate>Sat, 06 Feb 2010 13:52:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-3693</guid>
		<description>We are going to support IKEv2 EAP-TLS soon. Since EAP-TLS offers strong mutual authentication based on certificates there is not much sense in doing a certificate-based IKEv2 SGW authentication on top of that, so this will be a typical application for EAP_ONLY authentication.

Andreas</description>
		<content:encoded><![CDATA[<p>We are going to support IKEv2 EAP-TLS soon. Since EAP-TLS offers strong mutual authentication based on certificates there is not much sense in doing a certificate-based IKEv2 SGW authentication on top of that, so this will be a typical application for EAP_ONLY authentication.</p>
<p>Andreas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cristina_crow</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-3691</link>
		<dc:creator>cristina_crow</dc:creator>
		<pubDate>Sat, 06 Feb 2010 13:20:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-3691</guid>
		<description>@Andreas: cool. Good to know I can always count on Strongswan to be up to date with everything :) Thank you.</description>
		<content:encoded><![CDATA[<p>@Andreas: cool. Good to know I can always count on Strongswan to be up to date with everything <img src='http://www.imacandi.net/windancer/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas Steffen</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-3689</link>
		<dc:creator>Andreas Steffen</dc:creator>
		<pubDate>Sat, 06 Feb 2010 12:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-3689</guid>
		<description>strongSwan both supports draft-eronen-ipsec-ikev2-eap-auth:

http://www.strongswan.org/uml/testresults43rc/ikev2/rw-eap-sim-only-radius/

and RFC3739 Multiple Authentication:

http://www.strongswan.org/uml/testresults43rc/ikev2/mult-auth-rsa-eap-sim-id/

Since the EAP_ONLY notification hasn&#039;t been assigned yet by IANA, strongSwan uses a private value and sends a strongSwan Vendor ID. This will change as soon as draft-eronen-ipsec-ikev2-eap-auth has become an RFC.

Andreas</description>
		<content:encoded><![CDATA[<p>strongSwan both supports draft-eronen-ipsec-ikev2-eap-auth:</p>
<p><a href="http://www.strongswan.org/uml/testresults43rc/ikev2/rw-eap-sim-only-radius/" rel="nofollow">http://www.strongswan.org/uml/testresults43rc/ikev2/rw-eap-sim-only-radius/</a></p>
<p>and RFC3739 Multiple Authentication:</p>
<p><a href="http://www.strongswan.org/uml/testresults43rc/ikev2/mult-auth-rsa-eap-sim-id/" rel="nofollow">http://www.strongswan.org/uml/testresults43rc/ikev2/mult-auth-rsa-eap-sim-id/</a></p>
<p>Since the EAP_ONLY notification hasn&#8217;t been assigned yet by IANA, strongSwan uses a private value and sends a strongSwan Vendor ID. This will change as soon as draft-eronen-ipsec-ikev2-eap-auth has become an RFC.</p>
<p>Andreas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cristina_crow</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-3566</link>
		<dc:creator>cristina_crow</dc:creator>
		<pubDate>Fri, 29 Jan 2010 05:27:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-3566</guid>
		<description>@vmp: I will :D</description>
		<content:encoded><![CDATA[<p>@vmp: I will <img src='http://www.imacandi.net/windancer/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vmp</title>
		<link>http://www.imacandi.net/windancer/2010/01/28/rsa-keypair-radius-and-stokeos-for-ikev2-eap-authentication.html/comment-page-1#comment-3558</link>
		<dc:creator>vmp</dc:creator>
		<pubDate>Thu, 28 Jan 2010 20:30:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.imacandi.net/windancer/?p=1577#comment-3558</guid>
		<description>Close enough :P

We call mode-config &quot;mode-config&quot; because the name stuck from IKEv1 -- the IKEv2 literature AFAIK calls it &quot;configuration [payload]&quot;; no mode.

The freeradius patch is to work around Stoke&#039;s inconsistent identities (which trip up a paranoia check). And it&#039;s the wrong way of doing it -- we should add a config option :)

draft-eronen-ipsec-ikev2-eap-auth-07 is about allowing EAP in IKEv2 as the sole authentication method (as opposed to requiring the Responder to authenticate with certificates, which is what RFC4306 says).  You were probably thinking of RFC5106.

RFC4739 is not strictly about EAP; you could e.g. have two rounds of authentication with (different) certificates. RTFRFC, it has examples :D</description>
		<content:encoded><![CDATA[<p>Close enough <img src='http://www.imacandi.net/windancer/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>We call mode-config &#8220;mode-config&#8221; because the name stuck from IKEv1 &#8212; the IKEv2 literature AFAIK calls it &#8220;configuration [payload]&#8220;; no mode.</p>
<p>The freeradius patch is to work around Stoke&#8217;s inconsistent identities (which trip up a paranoia check). And it&#8217;s the wrong way of doing it &#8212; we should add a config option <img src='http://www.imacandi.net/windancer/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>draft-eronen-ipsec-ikev2-eap-auth-07 is about allowing EAP in IKEv2 as the sole authentication method (as opposed to requiring the Responder to authenticate with certificates, which is what RFC4306 says).  You were probably thinking of RFC5106.</p>
<p>RFC4739 is not strictly about EAP; you could e.g. have two rounds of authentication with (different) certificates. RTFRFC, it has examples <img src='http://www.imacandi.net/windancer/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

