Re: draft-kwatsen-reverse-ssh submission for review
Derek Fawcus <[email protected]>
| Newsgroups | gmane.ietf.saag,gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
On Fri, May 13, 2011 at 09:16:40AM +0200, t.petch wrote: > SSH does not authenticate the user or the application, it authenticates SSH. > > The proper solution is channel binding in which case it does not matter who > is SSH client and who is SSH server, and the existing SSH technology can > be reused unaltered. Quite. I recall looking at this a few years ago. The ssh protocols are largely symmetrical, as I recall it should be possible to flip roles once transport has completed, but before userauth or connection are started. .pdf