Re: [TLS] Review of draft-santesson-tls-gssapi-00
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] Review of draft-santesson-tls-gssapi-00
Stefan Santesson <stefans at microsoft.com> writes:
> Eric,
>
> I hear what you say. I still wander why that is a problem, more than
> philosophically.
> I said IF, we can take security out of the picture (if we can solve that issue so whatever GSS-API come up with, security is preserved), what is then the problem?
I've explained this as clearly as I can. Coupling two state machines
is a big deal and needs careful analysis. I haven't seen any.
As for taking security out of the picture, that was your claim not
mine. For me, this state machine issue *is* a security issue and
it's not purely an issue of establishing a key with a sufficiently
strong algorithm.
-Ekr
> Also provided that there are ways for the state machine to bail out and detect the end of the exchange, then what is the actual problem with that.
>
> To time consuming?
> To bandwidth consuming?
> To insecure anyway?
> just not pretty enough?
> Or something else..
>
> It doesn't seem very radical to me to have a protocol design which allows an arbitrary number or roundtrips for a sub process as long as the main process can bail out/timeout gracefully. It wouldn't be the first time in protocol design.
_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.