100 likes | 302 Views
Eduroam-ng. Klaas.Wierenga@surfnet.nl TF-Mobility, Barcelona, 6 September 2005. The current hierarchy. AA traffic goes through all intermediate entries All links are peer-to-peer agreements / static routes Authentication = authorization. Authenticate for everything?. Service attributes.
E N D
Eduroam-ng Klaas.Wierenga@surfnet.nl TF-Mobility, Barcelona, 6 September 2005
The current hierarchy • AA traffic goes through all intermediate entries • All links are peer-to-peer agreements / static routes • Authentication = authorization
Service attributes • Provider-id • SURFnet.nl • UVA.nl • Service-id • SVP • A-Select • WLAN • Dial-Up • Is this too fine-grained?
The tudelft.net/es.net/alfa-ariss.com case • Where to connect? • Who is going to manage that?
Towards p2p trust • Diameter • Implementations not ready for production, or are they? • DNSsec • New, hardly tested, requires adaptions to RADIUS servers • DNSROAM+RadSec • New, limited testing experience, supported in Radiator, not (yet?) in FreeRADIUS
RadSec + DNSROAM • RadSec: Secure Reliable Transport for RADIUS requests over TCP/IP using TLS • Encryption • Security • Message integrity • Strong mutual authentication • DNSROAM • Use DNS service records to locate the peer
DNS-Roam? RADSEC • DNSsec instead?
DNS-Roam transition phase RADSEC