Re: Servers that just want to have TLS

[email protected] (David P. Kemp) Fri, 9 May 1997 15:53:44 -0400
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
> From: "E. Gerck" <[email protected]>
> 
> Better, it can avoid mitm -- yes -- (which the other situation can't, of
> course), even without user authentication, if the anonymous user knows for
> sure a quality of the LDAP server -- which can be public.

The thing the user knows about the server must (not "can") be public.
Otherwise, by definition, you would be doing shared-secret authentication.


> It is a much more common misconception to think that you need at least one
> authenticated endpoint to avoid mitm.

I'm afraid I suffer from that misconception.  Could you post references
to a protocol that defeats mitm attacks without authenticating either
endpoint?