[openssl-dev] Replacing RFC2712 (was Re: Kerberos)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, May 11, 2015 at 11:25:33AM -0500, Nico Williams wrote:

>  - If you don't want to depend on server certs, use anon-(EC)DH
>    ciphersuites.
> 
>    Clients and servers must reject[*] TLS connections using such a
>    ciphersuite but not using a GSS-authenticated application protocol.

[*] Except when employing unauthenticated encrypted communication
to mitigate passive monitoring (oportunistic security).

-- 
	Viktor.


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux