Re: TLS clarifications (Re: Ordered delivery of EAP messages)
From: Lakshminath Dondeti (ldondetiqualcomm.com)
Date: Sat, 10 Mar 2007 21:10:03 -0800 (PST)
Yoshihiro Ohba wrote:
On Sat, Mar 10, 2007 at 02:37:11AM -0800, Lakshminath Dondeti wrote:
TLS requires reliable transport for replay protection. (I guess Bernard was trying to get at this in another context in this thread)

TLS requires reliable transport for implicit sequence number to work
for replay protection.

Right, that's what I was getting at.

But this does not mean replay attack is
possible if TLS is run over unreliable transport.

How is the sequence number maintained in that case? Are you saying that we might use an explicit sequence number as in DTLS? But, we are not discussing DTLS, are we?


What am I missing?

thanks,
Lakshminath

PS: To Avi's question, I was thinking in case of PEAP and TTLS if the EAP layer cannot guarantee in-order reliable delivery, how else do the endpoints maintain sequence numbers? If there is no other way, we can conclude that PEAP and TTLS require in-order reliable delivery for one of its security guarantees.


Yoshihiro Ohba

Results generated by Tiger Technologies using MHonArc.