[strongSwan] Authentication Payload after succesfull EAP-MD5 authentication

Martin Willi martin at strongswan.org
Thu Oct 21 13:19:56 CEST 2010


> How is the IKEv2 AUTH payload calculated after EAP-MD5 authentication?

As EAP-MD5 does not provide an MSK, SK_p is used instead.

> it should go exactly as for PSK authentication payload

Yes, it is exactly the same.

> except that the paddingstring is "Key Pad for EAP-IKEv2"

No, the key pad is the same as with PSK authentication.


More information about the Users mailing list