draft suggests that no negotiation of LAM type is possible between client and server: server can just accept or reject LAM type that client proposed, and he has no means to indicate to client which LAM type he is willing to do. This can lead to situation, when client will have to perform up to 4 connection attempts with different LAM types. Not only will it delay the connection setup, but also it will put an unnecessary load to server - for each attempt he will have to do both DH and RSA/DSA.
I think better way to handle this situation is to allow server to change LAM type if he doesn't like what client proposed.
--Paul Hoffman, Director --VPN Consortium