RE: Feedback on draft-ssh-ext-info-00

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <9A043F3CF02CD34C8E74AC1594475C73F4B9B382@uxcn10-5.UoA.auckland.ac.nz>
Damien Miller <[email protected]> writes:

>I'll repeat my opinion: an extension mechanism is not the place to
>fundamentally retcon parts of the protocol. 

Why not?  I would have thought that's what it was there for.  TLS has been
using extensions to fix protocol problems for years without any real problems.
Taking one case that I'm pretty familiar with, the encrypt-then-MAC extension,
the impact was very minimal, you add an entry to an extension en/decoding
table, and then have a boolean flag to swap the order of calls to encrypt and
MAC routines.  It was, I dunno, maybe a dozen lines of code and a hour's work
to fix a problem that had been plagueing the protocol for at least fifteen
years.  It's a really easy way to fix issues in the protocol, I just wish SSH
had had an extension mechanism of the kind that Denis is working on a long
time ago.

Peter.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.