Julian,
 
What
would you think about putting a list of keys that are allowed during security
stage in Section 11? The reason I ask this is because currently you have to
read through each key to figure that out.
 
I
think the only keys allowed during security stage are:
 
SessionType
InitiatorName
TargetName
AuthMethod
And
all keys listed under AuthMethod along with all of their associated keys.
 
If
you don’t want to list them, can you please confirm that I am correct above
(e.g., HeaderDigest is not allowed in security stage)?
 
Eddy