[22232] in Kerberos

home help back first fref pref prev next nref lref last post

GSSAPI security for connection encryption

daemon@ATHENA.MIT.EDU (Markus Moeller)
Wed Aug 18 15:34:16 2004

Date: Wed, 18 Aug 2004 06:52:40 -0400 (EDT)
Message-Id: <200408181052.i7IAqeV2002948@fort-point-station.mit.edu>
Content-Disposition: inline
Content-Transfer-Encoding: binary
Mime-Version: 1.0
From: Markus Moeller <huaraz@moeller.plus.com>
To: kerberos@mit.edu
Content-Type: text/plain
Errors-To: kerberos-bounces@mit.edu


If I want to secure a connection between a client and a server with gssapi. I
have to cut the data into blocks to fit into the buffers used by gss_wrap and
gss_unwrap. Is there any check that these blocks are send in the right order and
not tampered with. As far as I understand it each block is protected, but not the
sequence of the blocks. 

Does this mean gssapi encryption on connections is flawed ?

Thanks
Markus


-- 
Markus Moeller <huaraz@moeller.plus.com>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post