  No.  The problem is different.

  Let’s say we have a proxy which uses *one* list for home servers.  In that case, I can take *everyones* roaming down with a simple configuration.

1) I sign up for a roaming consortium, as

2) When proxies ask for my RADIUS server information, I give them *my* certificate, and the RADIUS IP / port for

3) a user logs into the proxy with, and gets the RADIUS server IP/port

4) the certificate presented for that IP/port is for, so the roaming will fail

  As a result, the home server TLS information *must* be kept separate for each realm.

