Re: [TLS] TLS state machine
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [TLS] TLS state machine



On Thu, Mar 22, 2007 at 03:48:14PM +0100, Bodo Moeller wrote:

[...]
> This particular concern might be cured by requiring any specific
> GSS-API mechanism to provide to the TLS layer (an upper bound on) the
> number of messages to be exchanged before the GSS-API portion of the
> handshake actually starts.

Oops, the wording I chose here turns out to be ambiguous.  What I
meant is:

This particular concern might be cured by requiring any specific
GSS-API mechanism to provide to the TLS layer, before the GSS-API
portion of the handshake actually starts, (an upper bound on) the
number of messages to be exchanged.

>                             Then you could have the TLS layer do a
> count-down with handshake messages gss_token<n>, gss_token<n-1>, etc.,
> down to gss_token<1> (these count-down numbers being a purely internal
> concept, not appearing on the wire).


Bodo


_______________________________________________
TLS mailing list
TLS at lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.