[145181] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: "Against Rekeying"

daemon@ATHENA.MIT.EDU (Stephan Neuhaus)
Thu Mar 25 08:44:11 2010

From: Stephan Neuhaus <neuhaus@st.cs.uni-sb.de>
In-Reply-To: <881FA93B-5C9C-44D3-9869-2D69B2D93BDE@callas.org>
Date: Wed, 24 Mar 2010 10:07:36 +0100
Cc: "Perry E. Metzger" <perry@piermont.com>, cryptography@metzdowd.com
To: Jon Callas <jon@callas.org>


On Mar 23, 2010, at 22:42, Jon Callas wrote:

> If you need to rekey, tear down the SSL connection and make a new one. =
There should be a higher level construct in the application that =
abstracts the two connections into one session.

... which will have its own subtleties and hence probability of failure.

Stephan=

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post