Re: Feedback on draft-ssh-ext-info-00
[email protected] (Niels Möller)
| Newsgroups | gmane.ietf.secsh |
|---|---|
| Message-ID | <[email protected]> |
Damien Miller <[email protected]> writes: >> But but but I waaaant to replace this awful SSH_MSG_SERVICE_REQUEST. :) >> >> Does no one agree that SERVICE_REQUEST + ACCEPT are pointless? >> >> A whole round-trip delay? For no benefit - in any known usage >> scenario? I think the entire point of the "awful" design, where you don't get a second chance, just a disconnect in case the service isn't available, is to eliminate that roundtrip delay. You can send a service request for "ssh-userauth", followed back-to-back by userauth requests for "none", PK_OK, whatever querying you like. And one roundtrip later, you can compute the needed signature for a likely successful publickey userauth request. Regards, /Niels -- Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26. Internet email is subject to wholesale government surveillance.