Re: : FW: IPSec use with Diameter (from the IPSEC WG list)
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
Scott G. Kelly wrote: > I didn't comment on it before, but the reference to pre-shared keys here > confuses me. In IKEv1, use of PSK's is even more restrictive than use of > certs. Since they must be identified by the IP of the peer, there can > only be one psk per peer pair (say *that* three times really fast). How > does that solve the cert problem described here? I'm not sure. The certificate usage issue may be orthogonal. I do know some people have worried about how long certificate chains (possibly needed on an interdomain case) pass through UDP and how well fragmentation is supported over various cases. --Jari