[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: l2tp as ipsra solution



On Wed, 14 Jun 2000, Daniel Fox wrote:
> ...we need to think more generically.  Are there *any* authentication
> databases that do not protect the secrecy of one-way-encryption output?  After
> all, that is the point of one-way encryption, that you do not need to keep it
> secret.

We also need to think more specifically. :-)  Are there any *widespread*
authentication databases which don't protect the one-way-encryption output?
It is not reasonable to require that we support every mistake anyone has
ever made.  Handling the common, recent ones should suffice.

                                                          Henry Spencer
                                                       henry@xxxxxxxxxxxxx