ad-assurance - RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: Eric Goodman <>
- To: "" <>
- Subject: RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call
- Date: Fri, 4 Oct 2013 22:58:09 +0000
- Accept-language: en-US
I’d further note:
Two notes:
1)
I think he’s actually responding to the previous section (7.5), because of the focus on the “replay attack”. If you note, my typo is that both sections
end stating they “resist replay attacks” even though the second should say “resist eavesdropping”. 2)
I don’t think the issue is resisting vs. precluding replay. I think the question is about what is replayable/eavesdroppable. The password is clearly
replayable. The packet containing the password is not, because the protected channel keeps it from being so. Similarly, the packet is clearly eavesdroppable, but the unencrypted ciphertext is what is not eavesdroppable. And the measure of “how hard does it
need to be” is “it needs to be a protected channel”. I don’t think I’m saying anything new in #2, I’m just focusing more on the requirement being “use protected channels” as compared to arguing resist vs. preclude.
(The latter argument could lead you to using weaker cryptography that wouldn’t meet the IAP requirement). --- Eric From: [mailto:]
On Behalf Of David Walker Everyone, |
- [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, David Walker, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Michael W. Brogan, 10/04/2013
- Re: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, David Walker, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Capehart,Jeffrey D, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Michael W. Brogan, 10/04/2013
- Re: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, David Walker, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Ron Thielen, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Capehart,Jeffrey D, 10/04/2013
- Re: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, David Walker, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Eric Goodman, 10/04/2013
- Re: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, David Walker, 10/04/2013
- RE: [AD-Assurance] Quick notes from the 10/4/2013 AD Assurance call, Michael W. Brogan, 10/04/2013
Archive powered by MHonArc 2.6.16.