>>>>> "Eric" == Eric Rescorla <[EMAIL PROTECTED]> writes:

    Eric> As I understand DIX 16.2, the only way in which the MAC is
    Eric> used is for the Identity Agent to be able to determine that
    Eric> messages it has generated are valid. The MAC isn't verified
    Eric> by anyone else and a MAC is just a suggested implementation
    Eric> anyway. I'm not sure how automated key management would fit
    Eric> in here.

OK, if so then I am confused.  I thought I saw an instance where the
homesite and the visited site needed to share a MAC key in a previous
version.


_______________________________________________
dix mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/dix

Reply via email to