[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ssldump-users
Subject:    Re: Diffe Hellman?
From:       "Gregory Stark" <ghstark () pobox ! com>
Date:       2003-10-18 13:05:21
[Download RAW message or body]


> Ssldump seems to have trouble getting the session key out off a
> Diffie-Hellman key exchange.  Maybe this is because in Diffie-Hellman,
> ...

You are correct, ssldump cannot determine the session keys for DH
ciphersuites. And while it is true that unauthenticated DH exchanges are
vulnerable to MITM attacks, ssldump is not designed to do this for you.


======================
Greg Stark
ghstark@pobox.com
======================


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic