Paul Wouters <p...@nohats.ca> wrote:
    > Technically, your profile could say to "request transport mode, and
    > refuse the connection if the other end is unwilling to use transport
    > mode", but that I would argue that would constitute a protocol
    > modification which is not what a profile should do.

How is this different than:
  "request authentication with a RSA certificate known to this CA,
  and refuse the connection if the other end is unwilling to use an appropriate
  key"





--
Michael Richardson <mcr+i...@sandelman.ca>, Sandelman Software Works
 -= IPv6 IoT consulting =-



Attachment: signature.asc
Description: PGP signature

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to