D-4
CB3000 Client Bridge User’s Guide
summarizes the major differences between the protocols.
Table D-1. Detailed Comparison of TLS-based EAP Methods
EAP Type
TLS
(RFC 2716)
a
TTLS
(Internet draft)
b
PEAP
(Internet draft)
c
Software
Supported Client
Platforms
Linux, Mac OS X,
Windows 95/98/ME,
Windows NT/2000/
XP
Linux, Mac OS X,
Windows 95/98/ME,
Windows NT/2000/
XP
Windows XP
Authentication Server
Implementations by
Cisco, Funk, HP,
FreeRADIUS (open
source),
Meetinghouse,
Microsoft
Funk, Meetinghouse
Cisco
Authentication
Methods
Client certificates
Any
Generic token card
Protocol Operations
Basic Protocol Structure Establish TLS session
and validate
certificates on both
client and server
Two phases:
• Establish TLS
between client and
TTLS server
• Exchange attribute-
value pairs between
client and server
Two parts:
• Establish TLS
between client and
PEAP server
• Run EAP exchange
over TLS tunnel
Fast Session Reconnect No
Yes
Yes
WEP Integration
Server can supply WEP key with external protocol (e.g. RADIUS
extension)
PKI and Certificate Processing
Server Certificate
Required
Required
Required
Client Certificate
Required
Optional
Optional
Certificate Verification
Through certificate chain or OCSP TLS extension (current Internet
draft)
Effect of Private Key
Compromise
Re-issue all server
and client certificates
Re-issue certificates for servers (and clients if
using client certificates in first TLS exchange)
Client and User Authentication
Summary of Contents for CB3000 - Client Bridge - Wireless Access Point
Page 1: ...M CB3000 Client Bridge User s Guide ...
Page 24: ...2 12 CB3000 Client Bridge User s Guide ...
Page 65: ...Management Options 4 7 Figure 4 4 View Log Screen ...
Page 74: ...4 16 CB3000 Client Bridge User s Guide ...
Page 90: ...5 16 CB3000 Client Bridge User s Guide ...
Page 94: ...B 2 CB3000 Client Bridge User s Guide ...
Page 96: ...C 2 CB3000 Client Bridge User s Guide ...
Page 104: ...D 8 CB3000 Client Bridge User s Guide ...
Page 105: ......