I still have no complete answer from the SEC ADs... But a start might be document draft-iab-sec-cons-00.txt specifically sect 4.5.1 Hope this gets you started Bert > > ><draft-ietf-mpls-generalized-rsvp-te-07.txt> > > > > > >1. This doc says "just use IPsec". A clearer statement is needed, > > > specifying the necessary IPsec selectors (per RFC 2401) and the > > > way the cryptographically protected endpoints are related to > > > the authorization model, i.e., who can do what. > > > > can you provide an example of what you'd like to see? > > > > I am checking with Security ADs. >