[22232] in Kerberos
GSSAPI security for connection encryption
daemon@ATHENA.MIT.EDU (Markus Moeller)
Wed Aug 18 15:34:16 2004
Date: Wed, 18 Aug 2004 06:52:40 -0400 (EDT)
Message-Id: <200408181052.i7IAqeV2002948@fort-point-station.mit.edu>
Content-Disposition: inline
Content-Transfer-Encoding: binary
Mime-Version: 1.0
From: Markus Moeller <huaraz@moeller.plus.com>
To: kerberos@mit.edu
Content-Type: text/plain
Errors-To: kerberos-bounces@mit.edu
If I want to secure a connection between a client and a server with gssapi. I
have to cut the data into blocks to fit into the buffers used by gss_wrap and
gss_unwrap. Is there any check that these blocks are send in the right order and
not tampered with. As far as I understand it each block is protected, but not the
sequence of the blocks.
Does this mean gssapi encryption on connections is flawed ?
Thanks
Markus
--
Markus Moeller <huaraz@moeller.plus.com>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos