Re: : FW: IPSec use with Diameter (from the IPSEC WG list)

Bernard Aboba <[email protected]>
Newsgroups gmane.ietf.aaa
Message-ID <[email protected]>
> Theoretically, the initiator can be guided by configuration to choose
> the right certificate for the purpose that the phase 1 is being brought
> up for. This works as long as the responder is willing to accept any of
> the trust anchors. At the time phase 2 is being brought up, an
> authorization decision can determine whether the initiator did the
> right thing.
>
> But this is very brittle, does not involve any explicit communication
> over the protocols, and relies on correct configuration and knowledge
> about what the other side expects. As a result it may not be very easy,
> particularly in an inter-domain case.

This was exactly the limitation that RFC 3588 is talking about.  Note that
it is possible that the certificates themselves may be different in
important ways.  And the Responder might itself require a different
certificate. For example, a certificate for use of RADIUS over IPsec
might be different between a RADIUS client and server.  In that case the
Responder doesn't even know if the certificate is valid for the intended
usage, or which certificate it is to use itself, until Phase 2.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.