RE: Zebedee Analysis

"William Hazelrig" <[email protected]> Mon, 12 Apr 2004 16:24:30 -0500
Newsgroups gmane.comp.security.zebedee.general
Message-ID <000001c420d4$8c656f70$6563a8c0@HelpdeskTest>
If you implement identity checking, Zebedee 2.4.1 is not subject to
man-in-the-middle attacks.  See the Identity Checking section of the Zebedee
manual:

http://www.winton.org.uk/zebedee/manual.html

- w.h.

-----Original Message-----
From: zebedee-talk-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
[mailto:zebedee-talk-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org] On Behalf Of Yves Smolders
Sent: Thursday, April 08, 2004 1:31 AM
To: [email protected]
Subject: [Zebedee-talk] Zebedee Analysis


Hi guys,

A client where I want to implement ZBD as VPN is worried about the security
of the protocol.  I've found some links about blowfish & diffie-helmann, but
not an analysis of ZBD itself.

I know 2.4.1 has issues with man-in-the-middle attacks, but I believe 2.5.x
solves this with the contect checking (against replay attacks?)

Is there any independent analysis out there, like there used to be for
vtunnel?

Thanks,
Yves



-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id70&alloc_id638&op=click