Re: [TLS] simplistic renego protection
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [TLS] simplistic renego protection
Nelson B Bolyard wrote:
... what is a "lenient server"?
Is it a vulnerable server?
Yes.
Some servers apparently cannot function without renegotiation.
They will need to continue providing service to unpatched
clients for some amount of time and thus remain vulnerable.
The solution we publish must make it impossible for a lenient-
but-patched client and a lenient-but-patched server to be
successfully attacked by a MitM using the renegotiation bug.
Mike
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.