Re: : FW: IPSec use with Diameter (from the IPSEC WG list)
Bernard Aboba <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
> John, do you remember why we put it in this > text? I don't believe that the text is incorrect. While the IKEv1 initiator may know what port the phase I SA is intending to protect, the responder cannot know this because that information is not included in the IKEv1 phase 1 exchange. It doesn't matter how many phase 1 SAs are brought up between the two endpoints. The responder has no idea what the phase 1 SA is being brought up for, and so is unable to enforce different certificate policies based on the (undisclosed) application. In phase 2 the information is available, but by then it's too late.