> I have not read the document yet, but why are attributes included in > the reject response? Is it simply to get another round trip, or > something more complicated than that? It's about saving a round-trip. They could have easily put the VSA in an Access-Challenge, and accomplished the same goal.