Diffie-Hellman Questions

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, May 24, 2016 at 05:08:38PM +0000, Salz, Rich wrote:

> > 2) Are the same encryption keys used every time with ADH?
> 
> Yes.  That's the other BIG reason :)  You really want ephemeral, and therefore ECDH

NO, Rich is making a mistake, ADH is ephemeral of necessity, since
without long-term keys in certificates it is impossible to use
long-term keys whose disclosure might later compromise confidentiality.

> > 3) Is it possible to use ephemeral DH without using certificates?  I was not
> > able to get that to work.
> 
> Yes.  This is "null" auth.

Essentially:

    aNULL == (ADH || AECDH).

-- 
	Viktor.


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux