[107978] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: refactoring crypto handshakes (SSL in 3 easy steps)

daemon@ATHENA.MIT.EDU (James A. Donald)
Tue Nov 13 20:43:00 2007

Date: Wed, 14 Nov 2007 11:29:14 +1000
From: "James A. Donald" <jamesd@echeque.com>
To:  Pasi.Eronen@nokia.com
CC:  cryptography@metzdowd.com
In-Reply-To: <B356D8F434D20B40A8CEDAEC305A1F2404DA7F68@esebe105.NOE.Nokia.com>

Pasi.Eronen@nokia.com wrote:
 > The "extra messages" might be irrelevant for
 > cryptography, but they're not irrelevant for security
 > or functionality.
 >
 > E.g. in SSL, you have capability/feature negotiation
 > (cipher suites, trusted CAs, in TLS 1.2 also signature
 > algorithms, etc.)

You can handle this by client making a guess, perhaps
based on past experience, as to whether its initial
request for preferred protocol is likely to be accepted,
and if it thinks it probably will be, going ahead on the
assumption it will be, rather than waiting for the round
trips to complete.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post