Re: RFC2385 (MD5 signature in TCP packets) support

From: David S. Miller (davem@redhat.com)
Date: Fri Mar 15 2002 - 18:16:28 EST


   From: David Schwartz <davids@webmaster.com>
   Date: Fri, 15 Mar 2002 15:13:59 -0800
   
           There is no problem with MD5 that makes it unsuitable for this
   particular application. A SHA signature would enlarge each packet,
   further reducing the effective MTU. This would increase the cost of
   what was intended to be a simple mechanism to solve a specific
   problem (spoofed SYNs/RSTs).

Ignoring valid RST frames breaks TCP.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Fri Mar 15 2002 - 22:00:22 EST