Re: Servers that just want to have TLS
[email protected] (David P. Kemp) Fri, 9 May 1997 15:53:44 -0400
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
> From: "E. Gerck" <[email protected]> > > Better, it can avoid mitm -- yes -- (which the other situation can't, of > course), even without user authentication, if the anonymous user knows for > sure a quality of the LDAP server -- which can be public. The thing the user knows about the server must (not "can") be public. Otherwise, by definition, you would be doing shared-secret authentication. > It is a much more common misconception to think that you need at least one > authenticated endpoint to avoid mitm. I'm afraid I suffer from that misconception. Could you post references to a protocol that defeats mitm attacks without authenticating either endpoint?