Introduces MACsec EAP-TLS authentication session concepts, covering authentication limits, device roles, prerequisites, local authentication models with legacy TLS 1.3 KDF, encryption processes, and comprehensive configuration tasks for secure MACsec deployment.
A MACsec EAP-TLS authentication session is a certificate-based exchange that
-
uses Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) for peer authentication
-
enables mutual authentication between authentication server and client, and
-
derives the Master Session Key (MSK) that is used for MKA key material.
Additional reference information
-
EAP-TLS utilizes certificates for mutual authentication between routers.
-
After successful authentication, EAP-TLS generates the MSK, which is used to derive the Connectivity Association Key (CAK).
-
The Connectivity Association Key Name (CKN) is derived from the EAP session ID.