Re: Servers that just want to have TLS

Donal Arundel <[email protected]>
Newsgroups gmane.ietf.apps-tls
Message-ID <2.2.32.19970509092833.00363c74@eng-mail>

At 17:52 08/05/97 -0300, E. Gerck wrote:
>Yes, but public does not mean it should be left open for mitm and other
>attacks.
>
>You don't need authentication to encrypt. You are just guaranteeing a
>private and secure channel.
>
>I think that LDAP could most surely benefit from that, specially in
>situations like blind signatures.

Yes, but encryption without authentication doesn't actually guarantee
you a private channel. It just gives you a private channel to an 
unauthenticated endpoint and thus is subject to a man in the middle 
attack. The mitm can just listen and pass data to and from the 
intended recipient.

>
>Yours,
>
>Ed Gerck

Regards,
        Donal
----------------------------------------------------------------------------
Donal Arundel				email: [email protected]
IONA Technologies                  	tel : (Dublin) +353 1 6625255 x2418
The IONA Building		  	      (US)   1-800-orbix4u (6724948)
8-10 Lower Pembroke St               	fax : +353 1 6625244
Dublin 2, Ireland
----------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.