Auth is useless on its own but is used by many things - in fact it's not 
even used directly by an AOR. It's configured on an endpoint to do 
authentication of inbound traffic from that endpoint. It's also used by 
outbound registration and outbound publish in response to challenges.

While it would be possible to combine them you've now got duplicated 
stuff across different configuration items, both for configuration and 
also from an implementation perspective. As it is done right now *all* 
of the authentication is the same code for everything and there is no 
duplication. Fix a bug in it and you fix it for everything.

> I think auth's only use would be when all the aor's would register using
> the exact
> same credentials, and even then it would only save a small amount.

I don't understand what you mean.

> But I bet you're now going to say, those small amounts are going to add up..

