To delegate authentication to a CA in IKE, you need a certificate whose subjectAltName matches something that makes sense -- such as being the hostname or username or friendly name. This is what we're trying to avoid.
Yes, I don't see any reason to keep IKE active after the SIP BYE.
--Richard
_______________________________________________ mmusic mailing list mmusic at ietf.org https://www1.ietf.org/mailman/listinfo/mmusic