ietf-openpgp
[Top] [All Lists]

Re: Proposed Extensions to TLS for OpenPGP

1998-01-01 13:59:36
-----BEGIN PGP SIGNED MESSAGE-----

In <v0310280ab0d195b3e11b(_at_)[208(_dot_)129(_dot_)55(_dot_)202]>, on 01/01/98 
   at 10:58 AM, Steve Schear <schear(_at_)lvdi(_dot_)net> said:

Sure it does. (Hello, are you listening?) Fortify modifies the currently
shipping, currently export approved Navigator/Communicator, allowing
users anywhere to use its 128-bit SSL whenever they connect with a
128-bit capable SSL server (say a cypherpunk server at XS4all in the
Netherlands).  Normally, 128-bit SSL is only enabled when these browsers
connect with an SSL server which has a "supercert" issued with U.S. gov't
approval (mostly to U.S. banks).

So strong crypto is now available, via an easily applied patch, to the
most widely used export approved product.

Another approach that I have been playing with is the use of local crypto
proxies.

One would have a HTTP/SSL proxie that uses strong crypto and comes with
source code. One mearly connects their web borwser to their proxie and the
proxie handles all the crypto. For non crypto sites it would just pass the
pages and requests through unmolested.

I have also looked into adding SSH capabilities to this so even non-SSL
sites one can still tunnel via SSH for an encrypted link.

A similar approach can be used for addressing the weak S/MIME crypto
produced by NS, MS, et al.

- -- 
- ---------------------------------------------------------------
William H. Geiger III  http://users.invweb.net/~whgiii
Geiger Consulting    Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 2.6.3a at: http://users.invweb.net/~whgiii/pgpmr2.html                 
       
- ---------------------------------------------------------------

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a-sha1
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000

iQCVAwUBNKwDrI9Co1n+aLhhAQED5wP/YrMxrU9KNXKI+3Lk/3bat4aKzT738uXl
hjrqKq6s5CL1+CGGaYUszivbTPDQg/aDR3AEgceepx3FgIFSNR6Mh0oLsoKFVC+9
Ieh4YP+9Gh2D/PDjd3kYxeCKK2fxZWB/C6cHDsxRXMtO1k5raYE1SoptPozXICs5
Lh62RvT27fw=
=0jh6
-----END PGP SIGNATURE-----


<Prev in Thread] Current Thread [Next in Thread>