Updated description of TNC scenarios concerning RFC 7171 PT-EAP support

This commit is contained in:
Andreas Steffen
2014-06-26 09:47:03 +02:00
parent 21aebe3781
commit 75598e5053
6 changed files with 30 additions and 24 deletions
@@ -1,10 +1,11 @@
The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each to gateway <b>moon</b>
using EAP-TTLS authentication only with the gateway presenting a server certificate and
the clients doing EAP-MD5 password-based authentication.
In a next step the EAP-TNC protocol is used within the EAP-TTLS tunnel to determine the
health of <b>carol</b> and <b>dave</b> via the <b>TNCCS 2.0 </b> client-server interface
compliant with <b>RFC 5793 PB-TNC</b>. The IMC and IMV communicate are using the <b>IF-M</b>
protocol defined by <b>RFC 5792 PA-TNC</b>.
<p/>
In a next step the <b>RFC 7171 PT-EAP</b> transport protocol is used within the EAP-TTLS
tunnel to determine the health of <b>carol</b> and <b>dave</b> via the <b>IF-TNCCS 2.0 </b>
client-server interface compliant with <b>RFC 5793 PB-TNC</b>. The IMCs and IMVs exchange
messages over the <b>IF-M</b> protocol defined by <b>RFC 5792 PA-TNC</b>.
<p>
The first time the TNC clients <b>carol</b> and <b>dave</b> send their measurements,
TNC server <b>moon</b> requests a handshake retry. In the retry <b>carol</b> succeeds