On 6/7/20 4:52 PM, Salz, Rich wrote:
Because the TCP headers aren't part of the hmac digest? Am I missing
something?
And how does that affect the application data? What corruption of TCP headers would not end up being noticed at the application layer and therefore TLS?
well, it could send it to the wrong port, but i'll guess that tls is on
to that problem. i mean, it kind of sounds like you're saying the
transport checksum failing isn't a big deal? creating a gigantic window
would certainly not be a good thing in the face of congestion. transport
mode ipsec wouldn't suffer those kinds of problems.
Mike