On Jan 26, 2010, at 9:33 AM, Avi Lior wrote:
-It would have been useful to allow VSA to be included in Access- Reject.So at least an SDO can return an Error-Cause of their own or even Authorization-Failure-Cause or Authentication-Failure-Cause instead of hacking the Reply-Message attribute.
Potentially useful, yes, but also "dangerous". If VSAs are allowed in Access-Reject messages, it becomes much harder to maintain the "no means no" doctrine.
-- to unsubscribe send a message to radiusext-request@ops.ietf.org with the word 'unsubscribe' in a single line as the message text body. archive: <http://psg.com/lists/radiusext/>