Re: AEAD in ssh

[email protected] (Niels Möller)
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
Bryan Ford <[email protected]> writes:

> I see that in 3.1 on “Encrypting the packet length”, you’ve suggested
> the same approach as one of the earlier approaches I suggested a while
> ago in the corresponding TLS discussion. That’s a reasonable approach
> and I think would work, but I wanted to make sure you’re aware of
> another alternative that I’ve come to think is both cleaner and safer:
> just embed the length of the next packet within the normal
> AEAD-encrypted payload of its immediately prior packet.

Thanks for the update. 

This could make a lot of sense for a new protocol or for a larger
protocol update. But I think adding the length field to the preceding
packet is a too large structural change of the ssh protocol to do just
to support AEAD ciphers.

Regards,
/Niels

-- 
Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.