1 Jun 2012 11:38
Re: Preventing cross-protocol attacks in TLS protocol
Nikos Mavrogiannopoulos <nmav <at> gnutls.org>
2012-06-01 09:38:10 GMT
2012-06-01 09:38:10 GMT
On Thu, May 17, 2012 at 9:52 PM, Marsh Ray <marsh <at> extendedsubset.com> wrote: > I think this is a good robustness improvement to the protocol and may bring > other benefits. I actually considered including a very similar change in > draft-ray-encrypted-handshake, but did not do so primarily due to scope. > However, draft-mavrogiannopoulos-tls-server-key-exchage does not protect > against the attack described. I have improved the document to handle the case where both server and client support the extension but the client does not require it to be present. This comes at the cost of reducing the server random bytes to 28. http://www.ietf.org/id/draft-mavrogiannopoulos-tls-cross-protocol-00.txt regards, Nikos
RSS Feed