| Re: Issue 392: Authorization Issues | <– Date –> <– Thread –> |
|
From: M. Vanderveen (mvandervn |
|
| Date: Tue, 6 Feb 2007 12:54:37 -0800 (PST) | |
[.. ]this should not allow the attacker to compromise other
authenticators or the backend authentication server"
New text:
Compromise of a single authenticator MUST
NOT compromise keying material held by any other authenticator within
the system, and SHOULD NOT allow the attacker to compromise the
backend authentication server
2. Compromise of Peer in section 5.1: hopefully this does not invalidate the idea of Group keys for multicast (if a Peer's group key is compromised, so will the group keys of other peers in his multicast group - can't be helped).
3. Last paragraph of Section 5.8 "
the backend authentication server can impersonate the authenticator ". Not really necessary to say this, especially since the guidelines say that the backend authentication server is a trusted party, yes?
<too long to be included w/o moderator approval>
Want to start your own business? Learn how on Yahoo! Small Business.
-
Re: Issue 392: Authorization Issues Bernard Aboba, February 5 2007
- Re: Issue 392: Authorization Issues Bernard Aboba, February 6 2007
- Re: Issue 392: Authorization Issues M. Vanderveen, February 6 2007
- Re: Issue 392: Authorization Issues Bernard Aboba, February 6 2007
-
Re: Issue 392: Authorization Issues M. Vanderveen, February 6 2007
-
Re: Issue 392: Authorization Issues Bernard Aboba, February 7 2007
- Re: Issue 392: Authorization Issues Lakshminath Dondeti, February 11 2007
-
Re: Issue 392: Authorization Issues Bernard Aboba, February 7 2007
Results generated by Tiger Technologies using MHonArc.