RE: Authentication Mechanism Matrix (was L2TP vs IPSEC)

Hi Glen,

> > Well, that was basically my point. None of the recent
> proposals have dealt
> > with the issue of authenticating both user and machine.

> Try L2TP/IPSec w/EAP-TLS.

I wasn't including that as a "recent proposal". I meant the more recent get
cert type drafts.

> > To be more precise, I should have asked: "What is the
> proposal for doing
> > this with user certs? Sign with both in MM5?"
> How can you authenticate a machine the same cert as the user?
>  Can't be
> done, i wouldn't think...

I meant if you had two different certs.

