1995-01-30 - Re: ESP Unix encrypted session protocol software

Header Data

From: Thomas Grant Edwards <tedwards@src.umd.edu>
To: Matt Blaze <mab@research.att.com>
Message Hash: be4c854c342e4b12b641ee208910429414aedeeeb6c9da407f7ba68a837b9544
Message ID: <Pine.SUN.3.91.950130141846.6455B-100000@zydeco.src.umd.edu>
Reply To: <9501301802.AA08512@merckx.info.att.com>
UTC Datetime: 1995-01-30 19:23:32 UTC
Raw Date: Mon, 30 Jan 95 11:23:32 PST

Raw message

From: Thomas Grant Edwards <tedwards@src.umd.edu>
Date: Mon, 30 Jan 95 11:23:32 PST
To: Matt Blaze <mab@research.att.com>
Subject: Re: ESP Unix encrypted session protocol software
In-Reply-To: <9501301802.AA08512@merckx.info.att.com>
Message-ID: <Pine.SUN.3.91.950130141846.6455B-100000@zydeco.src.umd.edu>
MIME-Version: 1.0
Content-Type: text/plain


On Mon, 30 Jan 1995, Matt Blaze wrote:

> And if you had a trusted secure key
> store on the remote host, you wouldn't really need to use Diffie-Hellman
> to establish the session key in the first place, since you could just
> store each user's pre-established session key in advance.

Right - using DH exchange is probably appropriate in situations where
there is no pre-established credentials for the party on the other
machine.  Inter-domain authentication while possible in theory is not
often carried out to any great extent in reality.  Companies don't trust
each other, or at least are not concerned by this lack of security for
inter-domain communications. 

-Thomas






Thread