3 Apr 2003 10:52
Re: IESG feedback on core drafts.
Frank Cusack <fcusack <at> fcusack.com>
2003-04-03 08:52:37 GMT
2003-04-03 08:52:37 GMT
On Mon, Mar 31, 2003 at 08:08:59AM -0800, Chris Lonvick wrote: > The "none" cipher is provided for debugging and should never be used > except for that purpose. It's cryptographic properties are > sufficiently described in RFC 2410. I believe the "none" cipher has legitimate uses besides debugging. You may want the authentication mechanisms provided by SSH, but not the data confidentiality. EG: you are copying already encrypted data between machines that have such low CPU power that encryption is a significant overhead. Even if you disagree, *it goes without saying* that you wouldn't use the "none" cipher where integrity/privacy matters. If you /were/ to keep this text, shouldn't 'should' be in caps? RFC 2410 seems too humorous to be referenced in a security considerations section. Maybe I'm just in a bad mood though. /fc
I am pushing to get it in Cisco, and I am trying to also get it on
Cyclades's roadmap.
Do you have any other vendors that we should hassle?
RSS Feed