[875] in WWW Security List Archive
Re: What's the netscape problem
daemon@ATHENA.MIT.EDU (Wayne Wilson)
Wed Sep 20 15:58:53 1995
Date: Wed, 20 Sep 1995 12:28:21 -0900 (PDT)
From: Wayne Wilson <wwilson@umich.edu>
To: www-security@ns2.rutgers.edu
In-Reply-To: <M702872.001.7kqa0.7429.950920143945Z.CC-MAIL*/O=650/PRMD=MCDERMOTT/ADMD=MCI/C=US/@MHS>
Errors-To: owner-www-security@ns2.rutgers.edu
On 20 Sep 1995 Greg.R.Hardison@nola.mcdermott.com wrote:
>
>
> There is some info on this at: http://www.tgc.com/websec/20460.html
>
Thanks for this pointer, Netscape here clearly states that the problem
is with both session keys and "its initial key-pair generation". The
session keys originate with the client, so new versions of client
software are needed. I am still not sure what key-pair's are being
referred to on the server, but it sounds like the RSA public/private key
pair.