Re: TLS renotiation

Kurt Zeilenga <[email protected]>
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
I've now posted my preliminary report on the general impact of TLS  
renegotiation on LDAP to the [email protected] list, for initial  
discussion there.  A final report will be made available later, likely  
posted to [email protected].

This message is available in our local archive of this list: http://www.openldap.org/lists/ietf-ldapext/200911/msg00000.html

Howard has already made a brief statement here regarding impact upon  
OpenLDAP Software on this list.  In short summary, only the "milder  
issue" applies to OpenLDAP Software (and seems to a very minor  
concern).  Clients can mitigate this issue as discussed in the  
report.  Servers can mitigate this issue by disabling TLS  
renegotiations within their TLS library.  Disabling TLS renegotiations  
in the server has side effects which might not be desirable in certain  
deployments.

-- Kurt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.