Re: issues 18, 15, 6 -- return routability
Jari Arkko <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Hi Francis, > - If the specific IP address can be found in the peer's certificate, > you can skip the test > >=> I maintain my proposal to change this into "if the specific IP address >is already authorized, you can skip the test". >This is more general (as there can be other ways to authorized an address) >and more accurate (so it should answer Vijay's concern). > > Agreed. I think we can close this issue now. (At first when I saw this I thought there might be an issue with regards to having clear implementation requirements. I.e. what is the minimum that an implementation has to do. But then I realized that the way that we are apparently going to write this is that the additional authorization mechanisms are optional, i.e. the minimum you have to do is to always do the test. It doesn't matter if you support certificates or xmlconf admin interface or look at the moon's phase...) --Jari