Re: Welcome to the ietf-apps-tls mailing list
Dennis Glatting <[email protected]>
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Message-ID | <[email protected]> |
Date: Tue, 6 May 1997 19:20:35 -0700 From: "Paul E. Hoffman" <[email protected]> > At 6:26 PM -0700 5/6/97, Dennis Glatting wrote: > > >It may be worthwhile to note the potential impact of a MIM > >altering the TLS keyword parameters, e.g., nuke "TLS.10" and > >"SSL3.0" in lieu of "SSL2.0", or nuke the TLS keyword > >altogether. > > I'm not sure what you mean by "impact". Section 5 says: > :After the TLS handshake has been completed, both parties MUST decide > :whether or not to continue based on the authentication and privacy > :achieved. > This is a MUST, not a SHOULD. A MIM altering the keyword would still have > to get by this final check. > If two parties permit a given set of all types, e.g., they support all three types, and the set is altered by a MIM, then the selected type will probably be the strongest of the altered set. If two parties support non-TLS connections and TLS connections and the TLS keyword is nuked, then a non-TLS connection may be established. Of course, a party could have knowledge of the other's capabilities, which is certainly possible, but does not scale. -dpg