IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: agent draft (was Re: Secure Shell: Milestone Update.)

Jeffrey Hutzelman <> writes:

> On Friday, March 18, 2005 02:44:00 PM +0100 Niels Möller
> <> wrote:

> > Login: Client asks server for encrypted private key. User types in
> > passphrase to decrypt it. Key is used to sign the session id, just
> > like for plain publickey authentication.


> My main concern at the moment is that the approach you describe would
> make it fairly easy to obtain a copy of the encrypted private key on
> which to perform an offline dictionary attack...

Right. That's why one would want to use something more sophisticated,
like SRP.


Home | Main Index | Thread Index | Old Index