>Being able to encrypt only the payload would be extremely useful in
>server-to-server communications in datacenters.

How usefull is it, when packet sniffing gets you both the key
and the encrypted data ?

I could understand it if the userinfo pointed to a PSK, but sending
the actual AES key as part of the request defeats any attempt at
privacy I can see ?

