> I think the original argument against suites came from observing how > many SSL had. I think that that was largely the result of TLS being specified at a time when RSA was still encumbered and bona-fide MAC functions had not been developed. We are talking about 3 MUST suites and 2 MAY suites maximum. IKE1 had 9 encryption ciphers alone. Phill