[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[IPSec] : exchange mode - query



Hi all,

in the security consideration of some Internet drafts (e.g. Diameter) I
found the statement that "When pre-shared keys are used for authentication,
IKE Aggressive Mode SHOULD be used, and IKE Main Mode SHOULD NOT be used".
Can someone explain why it's not recommended to use Main Mode with
pre-shared keys? It will be nice to have a reference to such explanation in
other docs.

with regards,
Lev Finkel