From owner-cvs-all Mon Jun 18 9:54:27 2001 Delivered-To: cvs-all@freebsd.org Received: from Awfulhak.org (gw.Awfulhak.org [217.204.245.18]) by hub.freebsd.org (Postfix) with ESMTP id AB3D637B401; Mon, 18 Jun 2001 09:54:18 -0700 (PDT) (envelope-from brian@Awfulhak.org) Received: from hak.lan.Awfulhak.org (root@hak.lan.Awfulhak.org [172.16.0.12]) by Awfulhak.org (8.11.4/8.11.4) with ESMTP id f5IGsHF13542; Mon, 18 Jun 2001 17:54:17 +0100 (BST) (envelope-from brian@lan.Awfulhak.org) Received: from hak.lan.Awfulhak.org (brian@localhost [127.0.0.1]) by hak.lan.Awfulhak.org (8.11.4/8.11.4) with ESMTP id f5IGsGh07484; Mon, 18 Jun 2001 17:54:16 +0100 (BST) (envelope-from brian@hak.lan.Awfulhak.org) Message-Id: <200106181654.f5IGsGh07484@hak.lan.Awfulhak.org> X-Mailer: exmh version 2.3.1 01/18/2001 with nmh-1.0.4 To: mi@aldan.algebra.com Cc: kris@obsecurity.org, brian@FreeBSD.org, cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org, brian@Awfulhak.org Subject: Re: cvs commit: src/usr.sbin/ppp ccp.c ccp.h command.c deflate.c fsm.c fsm.h ip.c mppe.c ppp.8 pred.c In-Reply-To: Message from mi@aldan.algebra.com of "Mon, 18 Jun 2001 12:44:41 EDT." <200106181644.f5IGig097507@misha.privatelabs.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Mon, 18 Jun 2001 17:54:16 +0100 From: Brian Somers Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG > On 18 Jun, Kris Kennaway wrote: > > On Mon, Jun 18, 2001 at 11:24:10AM -0400, Mikhail Teterin wrote: > >> > Log: > >> > Add support for stateful MPPE (microsoft encryption) providing > >> > encryption compatibility with Windows 2000. Stateful encryption > >> > uses less CPU but is bad on lossy transports. > >> > >> So, I suppose, I'll now be able to avoid using SSH and use PPP > >> with encryption over a device like host:port/tcp directly, without > >> the > >> set login "!ssh tunnel@host" > >> > >> Great! Thanks, > > > > Only if you trust microsoft not to have screwed up the crypto, like > > they usually do with their protocols. > > Well, I'm only planning to use the FreeBSD implementation of the > protocol, which, was done from scratch and audited. Or was it not? I'm afraid it hasn't been audited, but it's been tested fairly thoroughly against a win2k installation. If anyone is keen to audit it, feel free to ask me any questions. I didn't pass it by freebsd-audit. > -mi -- Brian http://www.freebsd-services.co.uk/ Don't _EVER_ lose your sense of humour ! To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message