Re: Servers that just want to have TLS
"E. Gerck" <[email protected]>
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 8 May 1997, Chris Newman wrote: > On Thu, 8 May 1997 [email protected] wrote: > > > Chris Newman said.. > > > First we need to realize that SMTP is a special case since it's an > > > unauthenticated protocol by default. > > > > It's not alone, LDAP is also such a case. > > I thought of that, but anything accessible via LDAP without authentication > doesn't need to be encrypted, since it's public anyway. > Yes, but public does not mean it should be left open for mitm and other attacks. You don't need authentication to encrypt. You are just guaranteeing a private and secure channel. I think that LDAP could most surely benefit from that, specially in situations like blind signatures. Yours, Ed Gerck ______________________________________________________________________ Dr.rer.nat. E. Gerck [email protected] http://novaware.cps.softex.br P.O.Box 1201, CEP13001-970, Campinas-SP, Brazil - Fax: +55-19-2429533