Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 14 Aug 1999 11:35:09 -0700
From:      Nick Sayer <nsayer@quack.kfu.com>
To:        Kris Kennaway <kris@hub.freebsd.org>
Cc:        freebsd-hackers@freebsd.org
Subject:   Re: Whither makefiles for src/crypto/telnet/* ?
Message-ID:  <37B5B6DD.A2A2448B@quack.kfu.com>
References:  <Pine.BSF.4.10.9908141059190.78768-100000@hub.freebsd.org>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Kris Kennaway wrote:
> 
> On Fri, 13 Aug 1999, Dave Walton wrote:
> 
> > If you really want to work on an encrypted telnet, check out The
> > Stanford SRP Authentication Project (http://srp.stanford.edu/srp/).
> > I'd love to see SRP integrated into the FreeBSD telnet/telnetd.
> 
> I got started on this, to the extent of storing the SRP data in the passwd
> file as an additional password crypt() method

That will be incompatible with folks who, for example, use the old
style passwords in a YP map in order to be compatible with other
platforms
in the same domain.

As long as you require a shared secret there will be either extra
overhead
to maintain it (in a separate password database) or an exclusion of some
platforms because of inabilities to generate the shared secret (because
they have different crypt()s than we do).

Not requiring a shared secret allows monkey-in-the-middle. But the goal
here is to do better than nothing at all while not adding any
administrative
overhead. If you add overhead, people won't use it. SRA is a compromise
between security and ease of use. "Compromise" is not a four letter
word.
[-- Attachment #2 --]
0
	*H

0
10	+0	*H
300f=ޅG
0
	*H
010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated0
990621000000Z
000620235959Z010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. by Ref.,LIAB.LTD(c)9810UPersona Not Validated1301U*Digital ID Class 1 - Netscape Full Service10UNicholas W. Sayer1#0!	*H
	nsayer@quack.kfu.com00
	*H
0uSDp0<ԒQXQ\A3
wҒcvSp皞X@1Qj>Dس9M']ٻF\Bв
:{	8cıPl
o00	U00U 00`HE00(+https://www.verisign.com/CPS0b+0V0VeriSign, Inc.0=VeriSign's CPS incorp. by reference liab. ltd. (c)97 VeriSign0	`HB0
`HExvd4652bd63f2047029298763c9d2f275069c7359bed1b059da75bc4bc9701747da5d3f2141beac23ec2fd820bab6df5d711499fa1bc44f5f3ea450c03U,0*0(&$"http://crl.verisign.com/class1.crl0
	*H
PʿC79ەCɓgJgvbyN9.KLwAh~)]fV5O,c=r͈jO9YQ@*81x0smr0.0v.=}%]
u0
	*H
0_10	UUS10U
VeriSign, Inc.1705U.Class 1 Public Primary Certification Authority0
980512000000Z
080512235959Z010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated00
	*H
0ZDUz-Ox6
JoTw*h1ApzKHV-BD\B/;'
]6B3nTOJƚj$e~7jJ	|0z0	`HB0GU @0>0<`HE0-0++www.verisign.com/repository/RPA0U00U0
	*H
7;ڔ7qjm/d8[jI}g-,ݚB>V*3ǾSLýIBc¦]XI<\Ue  _Xj<n1<080010U
VeriSign, Inc.10UVeriSign Trust Network1F0DU=www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated=ޅG
0	+0	*H
	1	*H
0	*H
	1
990814183511Z0#	*H
	1QX&Zrج0R	*H
	1E0C0
*H
0*H
0+0
*H
@0
*H
(0
	*H
cYNu
.2nH%#@]	yM]Of#q[rFqA&`gq
|k
|~4[1'X!FmբiA{$(B|S!#MPJ+
home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?37B5B6DD.A2A2448B>