[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: RFC3576bis and Session State



David B. Nelson <> allegedly scribbled on Monday, May 28, 2007 12:14 PM:

> Glen Zorn writes...
> 
>> I'm saying that it is quite possible (& efficient) to authorize a
>> variety of services with a single Access-Accept, not all of which may
>> be instantiated simultaneously.
> 
> Using a single Service-Type attribute?  Which one?  I'm not aware of
> any RADIUS service types that convey a multi-session connotation. 

Service-Type is by no means the only way to signal service
authorization; in fact (in a move shortsighted even by IETF standards
;-) RADIUS only allows the authorization of the use of one framed
protocol at a time, even though PPP doesn't have this restriction &
multi-stack machines existed even back then.  I mention this only to
point out the inadequacy of RADIUS' existing session model, which I
think is pretty relevant.

> 
> Or are you thinking of VSAs?  I remember doing something like that
> back in my days at DEC, as a VSA. 

Possibly, yes.  

--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>