Re: : FW: IPSec use with Diameter (from the IPSEC WG list)
Bernard Aboba <[email protected]>
| Newsgroups | gmane.ietf.aaa |
|---|---|
| Message-ID | <[email protected]> |
> Theoretically, the initiator can be guided by configuration to choose > the right certificate for the purpose that the phase 1 is being brought > up for. This works as long as the responder is willing to accept any of > the trust anchors. At the time phase 2 is being brought up, an > authorization decision can determine whether the initiator did the > right thing. > > But this is very brittle, does not involve any explicit communication > over the protocols, and relies on correct configuration and knowledge > about what the other side expects. As a result it may not be very easy, > particularly in an inter-domain case. This was exactly the limitation that RFC 3588 is talking about. Note that it is possible that the certificates themselves may be different in important ways. And the Responder might itself require a different certificate. For example, a certificate for use of RADIUS over IPsec might be different between a RADIUS client and server. In that case the Responder doesn't even know if the certificate is valid for the intended usage, or which certificate it is to use itself, until Phase 2.