midcom-4 Page:2
1  2  3  4  5  6  7  8  9  10  11  12 

New Security Mechanism
CMS is gone
Turns out we need client signatures
Want to allow high quality shared secrets
Secur-ID
Kerberos
Not easy to implement

New Solution
TLS connection to the server
STUN request for asking for OTP
STUN response contains OTP
Use that OTP to generate HMAC on request
Server uses OTP to generate HMAC on response