Re: authentication (SRP*, DH, TLS)



xmath wrote:

[snip]


c'mon, you know you want to use TLS instead ;-)

ok, so when I implement TLS by using the socket redirectors
with let's say OpenSSL (already used for TLS in HTTPS) what
protocol-options or -features do I need to use/enable if I want
to be MITM-proof. if you tell me we need a PKI or a secret private
root cert for that it gets hard to deploy.

I think investing my time into TLS would be good as that was the
next step anyway.

btw, what is the use of SRP-TLS?

.



Relevant Pages

  • Re: SMTP AUTH implementation question
    ... <SNIP> ... > SMTP AUTH mechanism as being a downside of this specific mechanism. ... clear over the network or spending resources on setting up a TLS ... I'd say that CRAM-MD5 is a nice simple alternative for some ...
    (sci.crypt)
  • Re: TLS question
    ... security to the domains with which you do business. ... In the absence of a specific request from a domain to use /only/ TLS ...
    (microsoft.public.exchange.admin)
  • Re: Replacing base openssl
    ... EHLO workstation.test.zip ... 250 DSN ... 220 2.0.0 Ready to start TLS ...
    (comp.unix.bsd.freebsd.misc)
  • Re: How to access different mailboxes?
    ... but the product isn't in beta any longer. ... without tls on port 80. ... I don't think the server listens on port 80 for IMAP. ...
    (microsoft.public.exchange.admin)
  • Re: Exchange 2003 TLS Queuing
    ... going outbound will be? ... you tell it to use TLS, then everything leaving your organization will ... so because there's a cert installed on the virtual server. ...
    (microsoft.public.exchange.admin)

Quantcast