In Issue 303, Pasi Eronen said:
""Operational model"?
Section 4.3 says "Crypto-agility solutions SHOULD NOT require changes to the RADIUS operational model, such as the introduction of new commands or maintenance of [additional] state on the RADIUS server."
I'm not sure what "operational" means here -- at first I thought it might mean "operations and management" (so the requirement would be basically "SHOULD not complicate life for administrators"), but the two examples given don't seem to fit that very well. And it seems any solution that e.g. derives fresh session keys will involve some small (but greater than zero) amount of additional state on clients and servers.
If the intent was really operations and management, perhaps the should be rephased something like "When using long-term shared secrets for authentication, crypto-agility solutions SHOULD NOT require more operations and management work than the current solutions."
"
|