![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Marsh Ray wrote: > Is this allowed? > > |--- session A anon ---| > |--- session B anon ---||-- resumed A --| > > I have heard that browsers may do this. Ouch -- I thought that I understood the attack, and now you've just given me another headache ;-) Do servers support a renegotiation that resumes a different session? That seems like a really bad idea. Since a resumption may always be refused, clients can't be relying on this behaviour. So we could compatibly specify that servers MUST NOT accept such a resumption. -- David-Sarah Hopwood ⚥ http://davidsarah.livejournal.com
Attachment:
signature.asc
Description: OpenPGP digital signature