IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: applying AES-GCM to secure shell: proposed "tweak"



On Wed, 15 Apr 2009, Nicolas Williams wrote:

>  - Retriable initial kex, for example (this is so that GSS-API auth
>    failure need not lead to the connection being closed).  For this I'd
>    use the reserved unsigned 32-bit int in the KEXINIT as a flags field
>    -- if both the client and the server have the flag set for re-triable
>    kex then GSS-API failure should not lead to connection closure.

That is a good idea IMO.

-d



Home | Main Index | Thread Index | Old Index