Re: SSL vs. SSL over tcp/ip



Volker Birk <bumens@xxxxxxxxxxx> (07-04-18 19:18:05):

You can place anything under SSL, be it TCP/IP, UDP/IP or even
something entirely different than IP.

That's not completely true. RFC 4346 says in it's introduction
already:

| At the lowest level, layered on top of some reliable transport
| protocol (e.g., TCP[TCP]), is the TLS Record Protocol.

This implies, that you cannot use UDP for TLS, because UDP is not
reliable.

Firstly we're talking about SSL, not TLS. Secondly, we have a free
layer 5, where we can make unreliable transport protocols reliable.


Regards,
Ertugrul Söylemez.


--
From the fact that this CGI program has been written in Haskell, it
follows naturally that this CGI program is perfectly secure.
.



Relevant Pages

  • Re: SSL vs. SSL over tcp/ip
    ... SSL is now TLS, and it's implemented using a reliable transport ... TLS is a new protocol, for which it currently happens to be that it uses ... From the fact that this CGI program has been written in Haskell, ...
    (comp.security.misc)
  • Re: Hardware firewall blocking L2TP/IPSec VPN
    ... Protocol Info ... Frame 162 ... [Coloring Rule Name: UDP] ... Next payload: Security Association ...
    (microsoft.public.isa.vpn)
  • Re: Allow Wimba Live Classroom via ISA 2004 on SBS 2003
    ... Maybe I can get it to work by defining the custom protocol with primary UDP ... If not a custom access rule, to what rule do I attach the custom protocol? ... Port Range From: 5998 To: 5998. ...
    (microsoft.public.windows.server.sbs)
  • Re: port=1026&reason=ICMPsent
    ... > Actually ICMP is a layered protocol the UDP protocol in question is a ... in the payload of an ICMP ... with a payload indicating it was in response to a UDP packet? ...
    (alt.computer.security)
  • Re: Source address in response always the same as target address in request?
    ... Most UDP based protocols do not have this requirement. ... it would not be the case that in the (mumble mumble) years ... that the interface even provided the ability for the application to ... The UDP protocol itself has no such requirement. ...
    (comp.protocols.time.ntp)