Summary

  • RFC 5296 compresses EAP re-authentication into one round trip, but the protected peer-server result, AAA delivery of a per-authenticator rMSK and lower-layer key use remain distinct state transitions.
  • A reliable receipt must bind sequence admission, server counter advance, Finish verification, rMSK destination and installation, TSK establishment and final access outcome without recording secret material.

One round trip contains several authorities

ERP was designed to avoid a full EAP method run when a peer moves to another authenticator. A peer that retains valid re-authentication material can send EAP-Initiate/Re-auth through the authenticator to an ER server and receive EAP-Finish/Re-auth in a single round trip. The server may be at home or local to the visited domain.

Speed changes neither the number of actors nor the meaning of their evidence. The authenticator passes the ERP messages. The ER server evaluates the peer's proof. AAA transports the resulting rMSK toward the authenticator. The peer independently derives that rMSK. A lower-layer protocol then establishes transient session keys that can enforce access.

Calling all of that “ERP succeeded” erases the very boundary an incident investigator needs.

Sequence admission is a server-side state change

EAP-Initiate/Re-auth carries a 16-bit sequence number, exactly one keyName-NAI, a cryptosuite and an authentication tag. The keyName-NAI identifies the re-authentication integrity key and the ER server realm. The sequence number begins at zero for a newly derived rRK.

The server first determines whether SEQ is at least the expected value, or whether it falls inside an allowed window and has not already appeared. It then checks whether the cryptosuite is acceptable and verifies message integrity with the rIK. Only after those decisions does it derive rMSK from rRK with SEQ as an input.

For a well-formed request the Finish repeats the received SEQ, while the server increments its local expected sequence or updates its replay window. That advancement is durable protocol state. If the reply or AAA leg is then lost, the fact that the server consumed a sequence number does not prove the other parties crossed the same boundary.

A receipt therefore needs the expected state before admission, the decision, the accepted SEQ, the window and prior-use result, and the state after admission. A packet capture showing a valid request is not a counter commit record.

Retransmission is not a new transaction

ERP makes the peer responsible for retransmission timers. A retransmitted EAP-Initiate retains the same EAP Identifier. A new, non-retransmission Initiate uses a different Identifier, especially while another exchange is outstanding. Finish must match the Identifier of the outstanding Initiate or be discarded.

This creates two coordinates: the EAP Identifier distinguishes an outstanding exchange, while SEQ binds replay protection and rMSK derivation. Collapsing them into a generic request ID can make a retry appear to be a second authorization or a new transaction appear to be a harmless retransmission.

The RFC recommends clearing authenticator re-authentication state after 300 seconds. That timeout is operational housekeeping, not proof that the server's sequence window, the peer's outstanding state and the authenticator's installed keys all expired together.

A protected Finish proves a narrower fact

The ER server protects EAP-Finish/Re-auth with rIK. The peer checks that it expected the returned SEQ under the named key, then verifies integrity. On success it derives the rMSK locally. At that moment, the lower-layer security-association protocol is ready to be triggered.

“Ready to be triggered” is a deliberate boundary. The Finish proves that a party holding the relevant rIK produced a response over the agreed ERP coordinates. It does not prove that AAA delivered the rMSK to the intended authenticator, that the authenticator accepted or installed it, that the peer and authenticator chose the same generation, or that TSK establishment completed.

The evidence chain needs separate timestamps and actors for Finish creation, Finish verification, AAA send and receive, rMSK installation, lower-layer start, lower-layer completion and access enforcement.

The rMSK is bound to one authenticator

The rMSK is derived from rRK using a fixed label, the accepted SEQ and output length. It serves the same purpose as an MSK at an authenticator, but a given rMSK must not be shared across multiple authenticators. Its lifetime cannot exceed the rRK lifetime.

When a new rRK is created, later rMSKs must come from it. Previously delivered rMSKs may remain in use until they expire. A rotation event is therefore not a global cutover receipt. Operators must know which authenticator received which rMSK generation, whether it installed that material and when earlier per-authenticator keys stopped enforcing access.

During bootstrapping, the distinction is even more visible. If transient session keys already rely on an earlier MSK, the lower layer may ignore the new rMSK or may establish a new TSK from it. Both choices can be conformant. Receipt is not use.

Concurrent ERP turns a counter into a window

A peer may run ERP simultaneously through several authenticators to the same ER server. Messages can arrive out of order. The server may therefore accept unused SEQ values inside a window rather than one exact next value; maintaining that window is a local matter.

The resulting verdict cannot be reconstructed from SEQ alone. Evidence needs the window bounds and generation, the accepted-set state, which authenticator carried each request and which entry was retired as used. Otherwise two valid concurrent exchanges look like replay, or a replay looks like tolerated reordering.

Local policy also means monitoring must observe configuration changes. Widening a window changes what the server accepts even when packet formats and keys remain untouched.

A failure may be hostile or merely incompatible

When processing fails, the server returns EAP-Finish/Re-auth with the failure result. If it holds a valid rIK, it protects that response. For an unacceptable cryptosuite it should offer acceptable choices. The peer verifies sequence and integrity before trusting the failure and may retry with a listed suite, deriving new domain and re-authentication keys when the PRF changes.

If replay or integrity checks fail, however, the peer cannot tell whether an attacker forged the failure or the parties simply lack a common cryptosuite. RFC 5296 therefore says to continue according to retransmission timers before declaring failure.

An unverifiable failure is ambiguity, not attribution. Alerting that labels it an attack discards the standards-defined alternative and can trigger unnecessary fallback or quarantine.

Current key possession is the admission ticket

RFC 6696 later obsoleted RFC 5296 while keeping backward compatibility. Among its clarifications, an ERP-capable authenticator or local ER server must check that it currently possesses valid root material before responding during implicit bootstrapping. A cached peer identity or old context is not enough.

This does not make current possession a final outcome. It qualifies the actor to take the next protocol step. The receipt must still connect that root generation to the accepted sequence, derived rMSK, target authenticator and lower-layer result.

The complete transaction receipt

Preserve rRK identity and expiry; keyName-NAI and realm; EAP Identifier; SEQ; replay-window bounds and used-set verdict; cryptosuite; Initiate integrity decision; server acceptance and expected-sequence transition; rMSK generation and one-authenticator binding; protected Finish result, Identifier and SEQ; AAA transaction and destination; authenticator receipt and install acknowledgement; peer verification and derivation; the MSK or rMSK selected for TSK establishment; lower-layer start and finish; access result; fallback to full EAP; retransmission history; and any channel-binding input and verdict.

Do not record the rIK, rRK or rMSK. The purpose is to prove which boundary each actor actually crossed.

Sources