Content deleted Content added
m caps |
|||
Line 131:
{{Main|IEEE 802.1X}}
The encapsulation of EAP over [[IEEE 802]] is defined in [[IEEE 802.1X]] and known as "EAP over LANs" or EAPOL.<ref>{{cite IETF|rfc=3748|title=Extensible Authentication Protocol (EAP)|section=3.3|sectionname=EAP Usage Within IEEE 802}}</ref><ref>{{cite IETF|rfc=3748|title=Extensible Authentication Protocol (EAP)|section=7.12|sectionname=Link Layer}}</ref><ref>IEEE 802.1X-2001, § 7</ref> EAPOL was originally designed for [[IEEE 802.3]]
When EAP is invoked by an 802.1X enabled [[Network Access Server]] (NAS) device such as an [[IEEE 802.11i-2004]] Wireless Access Point (WAP), modern EAP methods can provide a secure authentication mechanism and negotiate a secure private key (Pair-wise Master Key, PMK) between the client and NAS which can then be used for a wireless encryption session utilizing [[Temporal Key Integrity Protocol|TKIP]] or [[CCMP (cryptography)|CCMP]] (based on [[Advanced Encryption Standard|AES]]) encryption.
|