Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: re: Encryption strength
From: frankw @ in . net (Frank Willoughby)
Date: Tue, 3 Oct 95 23:06:00 -0400
To: firewalls @ GreatCircle . com

>From the desk of Padgett:

>Frank rites:
>>Actually, the key management problem was solved by V-ONE a couple of years
>>ago. (V-ONE is a firewall vendor).  
>
>>After the host & the firewall have mutually authenticated themselves to each 
>>other (to prevent node spoofing), the entire session is encrypted - with each 
>>session having a *different* (unique) encryption key.  
>
>Sounds wonderful but pray tell *how* do they authenticate each other ? Out-
>of-channel ? Nice thing about the Netscape reversal of the traditional
>mechanism is that a secure channel is created *before* any trust is exchanged.
>Given that, traditional means of authentication are possible without worry
>of sniffing. Spoofing yes, but not sniffing and us aunchient mainframers know
>how to handle spoofing 8*).

Would it suffice to say that it was good enough for NSA - and that it is the 
*only* Internet firewall used in a NSA-approved configuration?  In a public
forum, this is probably all I can say.



>						Warmly,
>							Padgett
>
>ps had an interesting conversation with the NSA today in which I was told that
>   it is OK to explain why the right side of a KW-26 card case has all them 
>   little dents - of course you will have to be shot afterwards...

You might also ask your contacts at the Puzzle Palace about how V-ONE does
mutual
authentication.

Best Regards,


Frank



Follow-Ups:
Indexed By Date Previous: Re: FW to FW FTP w/ no port > 1023
From: peter @ nmti . com (Peter da Silva)
Next: re: network address translation
From: Paul A Vixie <paul @ vix . com>
Indexed By Thread Previous: re: Encryption strength
From: "A. Padgett Peterson, P.E. Information Security" <PADGETT @ hobbes . orl . mmc . com>
Next: Re: Encryption strength
From: Rick Smith <smith @ sctc . com>

Google
 
Search Internet Search www.greatcircle.com