Re: Servers that just want to have TLS
Donal Arundel <[email protected]>
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <2.2.32.19970509092833.00363c74@eng-mail> |
At 17:52 08/05/97 -0300, E. Gerck wrote:
>Yes, but public does not mean it should be left open for mitm and other
>attacks.
>
>You don't need authentication to encrypt. You are just guaranteeing a
>private and secure channel.
>
>I think that LDAP could most surely benefit from that, specially in
>situations like blind signatures.
Yes, but encryption without authentication doesn't actually guarantee
you a private channel. It just gives you a private channel to an
unauthenticated endpoint and thus is subject to a man in the middle
attack. The mitm can just listen and pass data to and from the
intended recipient.
>
>Yours,
>
>Ed Gerck
Regards,
Donal
----------------------------------------------------------------------------
Donal Arundel email: [email protected]
IONA Technologies tel : (Dublin) +353 1 6625255 x2418
The IONA Building (US) 1-800-orbix4u (6724948)
8-10 Lower Pembroke St fax : +353 1 6625244
Dublin 2, Ireland
----------------------------------------------------------------------------