btns-1----Page:8
1  2  3  4  5  6  7  8  9 

Keying issues
Current authenticate mode
Shared secret (pre-deployed)
Cert. from known CA (pre-deployed)
>> a.k.a. STS or authenticated Diffie-Hellman
BTNS: anonymous mode
Self-signed cert
Raw certs (cert. from unknown CA)
No cert., no shared secret
>> Schneier’s “shared secret” shared secret, a.k.a. original Diffie-Hellman
PPT Version