
|
Keying issues Current authenticate mode Shared secret (pre-deployed) Cert. from known CA (pre-deployed) >> a.k.a. STS or authenticated Diffie-Hellman BTNS: anonymous mode Self-signed cert Raw certs (cert. from unknown CA) No cert., no shared secret >> Schneier’s “shared secret” shared secret, a.k.a. original Diffie-Hellman |