[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Reminder: automated key management is often required for new protocols





Alan DeKok <aland@nitros9.org> wrote:
...

Section 2.2: The manual key management for long-term session keys
meets the last criteria in this section:

The scale of each deployment is very limited.

Ideally, each long-term key in DTLS is shared only between one server
and one client. Each client-server pair shares a unique key, and those
keys are (ideally) not re-used across multiple client-server pairs.
There aren't many deployments that are smaller scale than two parties.
 
gwz> I don't think that by "deployment" they mean how many parties share a key
gwz> ;-); more like how many NASs to a server (which can be in the thousands).

...


Building a website is a piece of cake.
Yahoo! Small Business gives you all the tools to get online.