On 2/18/13 12:48 PM, "David Bantz" <dabantz at alaska.edu> wrote: >Are we in effect saying encryption of the response is enough protection >from service >spoofing? You can't encrypt to an unauthenticated (anonymous) SP, by definition. There is absolutely no notion of protecting against spoofing if one allows anonymous RP use. -- Scott