thanks, but that doesn't actually answer my first question. It only documents 
that a and b (alice and bob) arrive at the ZZ value independently. My question 
is actually concerning section 2.1.2 "Generation of Keying Material" in 
RFC2631. My interpretation is that both parties are expected to generate 
"keying material" per that section on their own, rather than one party doing 
so and transmitting the results to the other party. This may seem obvious to 
those steeped in the tradition here, but it perhaps isn't to outsiders (i have 
a foot in both worlds).



