[18673] in cryptography@c2.net mail archive
Re: [saag] status of SSL vs SHA-1/MD-5, etc.?
daemon@ATHENA.MIT.EDU (Ben Laurie)
Sun Oct 16 14:09:36 2005
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Sun, 16 Oct 2005 17:07:22 +0100
From: Ben Laurie <ben@algroup.co.uk>
To: "Steven M. Bellovin" <smb@cs.columbia.edu>
Cc: Alex Alten <alex@alten.org>, cryptography@metzdowd.com,
cfrg@ietf.org, saag@mit.edu
In-Reply-To: <20051016134612.442FB3BFD37@berkshire.machshav.com>
Steven M. Bellovin wrote:
> As Eric Rescorla and I showed, though, none of the network protocols
> are ready for deployment of a new hash function. That is, newer
> versions of OpenSSL support may SHA-256, but there's no way to
> negotiate such usage if you don't know the status of the system to
> which you're talking.
None of the ones you looked at you mean - your survey wasn't comprehensive.
--
http://www.apache-ssl.org/ben.html http://www.thebunker.net/
"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com