Re: : FW: IPSec use with Diameter (from the IPSEC WG list)

Bernard Aboba <[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
> John, do you remember why we put it in this
> text?

I don't believe that the text is incorrect.

While the IKEv1 initiator may know what port the phase I SA is intending
to protect, the responder cannot know this because that information is not
included in the IKEv1 phase 1 exchange.  It doesn't matter how many phase
1 SAs are brought up between the two endpoints.  The responder has no idea
what the phase 1 SA is being brought up for, and so is unable to enforce
different certificate policies based on the (undisclosed) application.

In phase 2 the information is available, but by then it's too late.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.