Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


SSL - Different procedures to authenticate Server and Client
.

  • To: [EMAIL PROTECTED]
  • Subject: SSL - Different procedures to authenticate Server and Client
  • From: Paulo Wilbert <[EMAIL PROTECTED]>
  • Date: 10 Sep 2004 00:27:20 -0000
.
 

Hi Folks,

Why in SSL the procedure to authenticate the Client (see 
below) is not the same to authenticate the Server (see 
below)? 

Client Authentication: "Does the user's public key 
validate the user's digital signature? The server checks 
whether the user's digital signature can be validated with 
the public key in the certificate. If so, the server has 
established that the public key asserted to belong to the 
user matches the private key that is used to create the 
signature and that the data has not been tampered with 
since it was signed"

Server Authentication: "Does the domain name in the 
server's certificate match the domain name of the server 
itself? This step confirms that the server is actually 
located at the same network address that is specified by 
the domain name in the server certificate. Although step 4 
is not technically part of the SSL protocol, it provides 
the only protection against a form of security attack 
known as a "Man-in-the-Middle Attack." Clients must 
perform this step and must refuse to authenticate the 
server or establish a connection if the domain names do 
not match. If the server's actual domain name matches the 
domain name in the server certificate, the client goes on 
to step 5."

Thanks,

Paulo.






---------------------------------------------------------------------------
Computer Forensics Training at the InfoSec Institute. All of our class sizes
are guaranteed to be 12 students or less to facilitate one-on-one
interaction with one of our expert instructors. Gain the in-demand skills of
a certified computer examiner, learn to recover trace data left behind by
fraud, theft, and cybercrime perpetrators. Discover the source of computer
crime and abuse so that it never happens again.

http://www.infosecinstitute.com/courses/computer_forensics_training.html
----------------------------------------------------------------------------


 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.