There’s a new Internet-Draft out that may be of interest to the 11bt community. It defines a new RADIUS attribute to indicate the security profile being negotiated between the STA and Authenticator. Analogously, for CNSA 1.0 the WLAN-AKM-Suite was used but
since the AKM is being overloaded and it does not indicate the particular parameter set being used inside of that AKM it’s necessary to now send the security profile. Hence this draft.
Please take a look. Substantive comments should be sent to radext@xxxxxxxx but if you’re not subscribed, and don’t want to just to send an email, you can send them here or to Ken or myself.
Regards,
Dan.
--
“the object of life is not to be on the side of the majority, but to
escape finding oneself in the ranks of the insane.” – Marcus Aurelius
On 8/6/26, 1:47 PM, "internet-drafts@xxxxxxxx" <internet-drafts@xxxxxxxx> wrote:
A new version of Internet-Draft draft-rich-radext-wlan-security-profile-00.txt
has been successfully submitted by Ken Rich and posted to the
IETF repository.
RADIUS has attributes that let an IEEE 802.11 authenticator report
the AKM suite and pairwise cipher selected for an association. That
is useful, but it is not enough anymore. IEEE 802.11, as amended,
also defines security profiles. A security profile is the complete
set of AKM, pairwise cipher, and related security capabilities
accepted for an association.
The problem is that the AKM and the pairwise cipher no longer maps to
a single security profile. Using these two values, the RADIUS server
cannot tell which of the security profiles was accepted.
This document defines the WLAN-Security-Profile RADIUS attribute.
The attribute reports the IEEE 802.11 security profile accepted by
the responder for the association. It complements the existing IEEE
802 network attributes.
The IETF Secretariat
To unsubscribe from the STDS-802-11-TGBT list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=STDS-802-11-TGBT&A=1