IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: applying AES-GCM to secure shell: proposed "tweak"



On Wed, 15 Apr 2009, Nicolas Williams wrote:

> > This seems to be the least horrible solution to the problem. It is
> > certainly the easiest to implement, which makes me think that it won't
> > be stuffed up.
> 
> Jeff Hutzelman objects that this violates the abstraction that the
> transport layer defines the binary packet encoding.  I don't give a
> damn.

I don't see how this objection works: KEX (inc. cipher/mac negotiation)
determines the parameters for the transport protocol. How does a KEX
change violate the transport abstraction?

-d



Home | Main Index | Thread Index | Old Index