> From: Scott Brim <scott.brim@xxxxxxxxx> > The encapsulation is not much of an obstacle to packet examination. There was actually a proposal a couple of weeks back in the WG to encrypt all traffic on the inter-xTR stage. The win in doing it in the xTRs, of course, is that you don't have to go change all the hosts, application by application: _all_ traffic, of any kind, from that site to any/all other sites which are encryption-enabled, will get a certain degree of confidentiality. Does this count as something the IETF can do reasonably quickly that will help somewhat? :-) Noel