Security Basics mailing list archives
SSL - Different procedures to authenticate Server and Client
From: Paulo Wilbert <pwilbert () uninet com br>
Date: 10 Sep 2004 00:27:20 -0000
Hi Folks, Why in SSL the procedure to authenticate the Client (see below) is not the same to authenticate the Server (see below)? Client Authentication: "Does the user's public key validate the user's digital signature? The server checks whether the user's digital signature can be validated with the public key in the certificate. If so, the server has established that the public key asserted to belong to the user matches the private key that is used to create the signature and that the data has not been tampered with since it was signed" Server Authentication: "Does the domain name in the server's certificate match the domain name of the server itself? This step confirms that the server is actually located at the same network address that is specified by the domain name in the server certificate. Although step 4 is not technically part of the SSL protocol, it provides the only protection against a form of security attack known as a "Man-in-the-Middle Attack." Clients must perform this step and must refuse to authenticate the server or establish a connection if the domain names do not match. If the server's actual domain name matches the domain name in the server certificate, the client goes on to step 5." Thanks, Paulo. --------------------------------------------------------------------------- Computer Forensics Training at the InfoSec Institute. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse so that it never happens again. http://www.infosecinstitute.com/courses/computer_forensics_training.html ----------------------------------------------------------------------------
Current thread:
- SSL - Different procedures to authenticate Server and Client pwilbert (Sep 10)
- <Possible follow-ups>
- SSL - Different procedures to authenticate Server and Client Paulo Wilbert (Sep 10)
- Re: SSL - Different procedures to authenticate Server and Client Jason Coombs PivX Solutions (Sep 13)