1362
Views
5
Helpful
1
Replies
Questions regarding ISE Key Wrap functionality
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-14-2022 11:10 PM
Hi Team,
Could someone please provide details on how ISE calculates message-authentication-code AVP and insert into Access-accept packet when Key Wrap is enabled?
The problem we have is that the HMAC calculation on the Access-accept received from ISE does not match with inserted 20 bytes of hmac sha1 value in AVP.
Note: ISE sends access-accept, so ISE likes access-request packet (from us) and ISE’s hmac validation on access-request packet is correct.
Regards,
Saurabh
Labels:
- Labels:
-
AAA
-
Identity Services Engine (ISE)
1 Reply 1

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2022 02:39 PM
Hello @coolsaurabh.hrc
I haven't used key wrap feature. Just curious, why you're using it, and whether you have discovered a weakness in the existing MPPE key exchange?
It sounds like the Access-Accept is being returned to the NAS, and all is well? Perhaps the HMAC in the Access-Accept should not match that sent in the Access-Request. Have you tried analysing this in Wireshark?
