Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] SSH Issues



Edward Middleton writes:

 > HTTPS relies on prior key exchange.  Without it you have no assurance
 > you are connecting directly to the site you intended and could even be
 > connecting through your neighbors hypothetical proxy.  The prior
 > authentication can be out of band (like ssh) i.e. self signed server
 > certificates, but unless it occurs the whole infrastructure offers no
 > meaningful security.

Yes, yes, yes, I understand that.  Would you like to move on and read
what I wrote?  Executive summary: I had a brain bubble and thought that
in Curt's application DNS data was somehow self-authenticating (see my
other posts for discussion and examples of such information).

This led to the discussion of validation vs. authentication, which
made no sense assuming we were all talking about DNSSEC as it actually
is, which (due to above-mentioned temporary insanity) I wasn't.  We
are now all on the same page about DNSSEC, we all have the same
definitions of validation/verification, authentication, encryption,
and authorization I believe.


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links